undici vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-11525Lowundici: undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matchingCVE-2026-12151Highundici: undici WebSocket client vulnerable to denial of service via fragment count bypassCVE-2026-9679Mediumundici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2026-6734Highundici: undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuseCVE-2026-6733Lowundici: undici vulnerable to HTTP response queue poisoning via keep-alive socket reuseCVE-2026-9697Highundici: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgentCVE-2026-9678Mediumundici: undici vulnerable to cross-user information disclosure via shared cache whitespace bypassCVE-2026-9675Highundici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypassCVE-2026-1526Highundici: Undici has Unbounded Memory Consumption in WebSocket permessage-deflate DecompressionCVE-2026-2229Highundici: Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits ValidationCVE-2026-1527Mediumundici: Undici has CRLF Injection in undici via `upgrade` optionCVE-2026-2581Mediumundici: Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoSCVE-2026-1528Highundici: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the clientCVE-2026-1525Mediumundici: Undici has an HTTP Request/Response Smuggling issueCVE-2026-22036Mediumundici: Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustionCVE-2025-47279Lowundici: undici Denial of Service attack via bad certificate dataCVE-2025-22150Mediumundici: Use of Insufficiently Random Values in undiciCVE-2024-38372Lowundici: Undici vulnerable to data leak when using response.arrayBuffer()CVE-2024-30261Lowundici: Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrectCVE-2024-30260Lowundici: Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelineCVE-2024-24758Lowundici: Undici proxy-authorization header not cleared on cross-origin redirect in fetchCVE-2024-24750Mediumundici: fetch(url) leads to a memory leak in undiciCVE-2023-45143Lowundici: Undici's cookie header not cleared on cross-origin redirect in fetchCVE-2023-23936Mediumundici: CRLF Injection in Nodejs ‘undici’ via hostCVE-2023-24807Highundici: Regular Expression Denial of Service in Headers

Stop the waste.
Protect your environment with Kodem.