OsVault/npm/undici
npm

undici

18 known vulnerabilities · 0 critical · 1 high

CVE-2025-22150

Use of Insufficiently Random Values in undici

Published Jan 21, 2025
CVE-2023-23936MEDIUM

CRLF Injection in Nodejs ‘undici’ via host

Published Feb 16, 2023
CVE-2022-31150MEDIUM

undici before v5.8.0 vulnerable to CRLF injection in request headers

Published Jul 21, 2022
CVE-2026-1526

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

Published Mar 13, 2026
CVE-2026-1528

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

Published Mar 13, 2026
CVE-2026-2581

Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS

Published Mar 13, 2026
CVE-2023-24807HIGH

Regular Expression Denial of Service in Headers

Published Feb 16, 2023
CVE-2024-38372LOW

Undici vulnerable to data leak when using response.arrayBuffer()

Published Jul 9, 2024
CVE-2026-1527

Undici has CRLF Injection in undici via `upgrade` option

Published Mar 13, 2026
CVE-2022-35948MEDIUM

Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type

Published Aug 18, 2022
CVE-2026-22036

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

Published Jan 14, 2026
CVE-2026-2229

Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation

Published Mar 13, 2026
CVE-2022-32210MEDIUM

ProxyAgent vulnerable to MITM

Published Jun 17, 2022
CVE-2022-31151LOW

undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect

Published Jul 21, 2022
CVE-2023-45143LOW

Undici's cookie header not cleared on cross-origin redirect in fetch

Published Oct 16, 2023
CVE-2022-35949MEDIUM

`undici.request` vulnerable to SSRF using absolute URL on `pathname`

Published Aug 18, 2022
CVE-2026-1525

Undici has an HTTP Request/Response Smuggling issue

Published Mar 13, 2026
CVE-2025-47279

undici Denial of Service attack via bad certificate data

Published May 15, 2025
Check your entire dependency tree at onceRun dependency scan →