Dependency scanning
Check whether undici is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-16729
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-15157
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-14643
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-13697
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVE-2026-9697
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
CVE-2026-9678
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
CVE-2026-9679
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-6733
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2025-22150
Use of Insufficiently Random Values in undici
CVE-2026-6734
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
CVE-2026-1526
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
CVE-2026-2229
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
CVE-2026-2581
Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
CVE-2026-1528
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
CVE-2026-1527
Undici has CRLF Injection in undici via `upgrade` option
CVE-2026-1525
Undici has an HTTP Request/Response Smuggling issue
CVE-2026-22036
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
CVE-2025-47279
undici Denial of Service attack via bad certificate data
CVE-2024-38372
Undici vulnerable to data leak when using response.arrayBuffer()
CVE-2026-12151
undici WebSocket client vulnerable to denial of service via fragment count bypass
CVE-2023-24807
Regular Expression Denial of Service in Headers
CVE-2024-24750
fetch(url) leads to a memory leak in undici
CVE-2024-24758
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
CVE-2023-23936
CRLF Injection in Nodejs ‘undici’ via host
CVE-2022-32210
ProxyAgent vulnerable to MITM
CVE-2026-9675
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2022-31151
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
CVE-2023-45143
Undici's cookie header not cleared on cross-origin redirect in fetch
CVE-2024-30261
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
CVE-2024-30260
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
CVE-2022-35949
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
CVE-2022-35948
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
CVE-2022-31150
undici before v5.8.0 vulnerable to CRLF injection in request headers
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes