Undici has an HTTP Request/Response Smuggling issue
Modified: 9/10/2026
package
pkg:npm/undici
Undici has an HTTP Request/Response Smuggling issue
Modified: 9/10/2026
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Modified: 9/10/2026
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Modified: 9/10/2026
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
Modified: 6/18/2026
undici before v5.8.0 vulnerable to CRLF injection in request headers
Modified: 11/8/2023
Undici vulnerable to data leak when using response.arrayBuffer()
Modified: 9/10/2026
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
Modified: 9/28/2026
Undici has CRLF Injection in undici via `upgrade` option
Modified: 9/10/2026
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
Modified: 9/10/2026
CRLF Injection in Nodejs ‘undici’ via host
Modified: 9/10/2026
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
Modified: 11/8/2023
undici vulnerable to downstream response desynchronization via retry interceptor
Modified: 9/10/2026
fetch(url) leads to a memory leak in undici
Modified: 9/10/2026
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Modified: 11/4/2025
Use of Insufficiently Random Values in undici
Modified: 9/10/2026
undici Denial of Service attack via bad certificate data
Modified: 9/10/2026
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Modified: 9/10/2026
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Modified: 11/8/2023
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
Modified: 9/10/2026
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Modified: 9/10/2026
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
Modified: 9/10/2026
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Modified: 9/10/2026
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Modified: 11/4/2025
undici vulnerable to CRLF Injection via blob-like body 'type' property
Modified: 9/10/2026
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
Modified: 9/10/2026
ProxyAgent vulnerable to MITM
Modified: 7/8/2026
Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
Modified: 9/10/2026
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
Modified: 9/10/2026
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
Modified: 2/4/2026
Regular Expression Denial of Service in Headers
Modified: 9/10/2026
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
Modified: 9/10/2026
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
Modified: 9/10/2026
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
Modified: 9/10/2026
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
Modified: 9/10/2026
undici WebSocket client vulnerable to denial of service via fragment count bypass
Modified: 9/10/2026
Undici's cookie header not cleared on cross-origin redirect in fetch
Modified: 2/4/2026