35 Total advisories
35 Vulnerabilities
0 Malware

Vulnerabilities

HIGH 7.4
npm

CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

MEDIUM 4.8
npm

CVE-2026-16729

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

MEDIUM 4.8
npm

CVE-2026-16728

undici vulnerable to downstream response desynchronization via retry interceptor

MEDIUM 4.2
npm

CVE-2026-15157

undici vulnerable to CRLF Injection via blob-like body 'type' property

MEDIUM 5.9
npm

CVE-2026-14643

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

HIGH 7.7
npm

CVE-2022-32210

ProxyAgent vulnerable to MITM

LOW 3.7
npm

CVE-2026-6733

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

HIGH 7.5
npm

CVE-2026-6734

undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

MEDIUM 5.9
npm

CVE-2026-9679

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

LOW 3.7
npm

CVE-2026-11525

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

HIGH 7.5
npm

CVE-2026-12151

undici WebSocket client vulnerable to denial of service via fragment count bypass

MEDIUM 5.9
npm

CVE-2026-9678

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

HIGH 7.4
npm

CVE-2026-9697

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

HIGH 7.5
npm

CVE-2026-9675

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

MEDIUM 5.9
npm

CVE-2026-2581

Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS

HIGH 7.5
npm

CVE-2026-1526

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

HIGH 7.5
npm

CVE-2026-1528

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

MEDIUM 6.5
npm

CVE-2026-1525

Undici has an HTTP Request/Response Smuggling issue

MEDIUM 4.6
npm

CVE-2026-1527

Undici has CRLF Injection in undici via `upgrade` option

HIGH 7.5
npm

CVE-2026-2229

Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation

LOW 3.1
npm

CVE-2025-47279

undici Denial of Service attack via bad certificate data

LOW 3.7
npm

CVE-2022-31151

undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect

MEDIUM 5.9
npm

CVE-2026-22036

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

LOW 3.9
npm

CVE-2023-45143

Undici's cookie header not cleared on cross-origin redirect in fetch

MEDIUM 6.8
npm

CVE-2025-22150

Use of Insufficiently Random Values in undici

LOW 2.6
npm

CVE-2024-30261

Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect

LOW 3.9
npm

CVE-2024-30260

Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

MEDIUM 4.6
npm

CVE-2023-23936

CRLF Injection in Nodejs ‘undici’ via host

LOW 2.0
npm

CVE-2024-38372

Undici vulnerable to data leak when using response.arrayBuffer()

LOW 3.9
npm

CVE-2024-24758

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

MEDIUM 6.5
npm

CVE-2024-24750

fetch(url) leads to a memory leak in undici

HIGH 7.5
npm

CVE-2023-24807

Regular Expression Denial of Service in Headers

MEDIUM 5.3
npm

CVE-2022-35949

`undici.request` vulnerable to SSRF using absolute URL on `pathname`

MEDIUM 5.3
npm

CVE-2022-35948

Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type

MEDIUM 5.3
npm

CVE-2022-31150

undici before v5.8.0 vulnerable to CRLF injection in request headers

Ready to move

Start Securing

Free, no credit card | First findings in minutes