35 Total advisories
35 Vulnerabilities
0 Malware

Dependency scanning

Check whether undici is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 4.8
npm

CVE-2026-16729

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

MEDIUM 4.2
npm

CVE-2026-15157

undici vulnerable to CRLF Injection via blob-like body 'type' property

MEDIUM 5.9
npm

CVE-2026-14643

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

MEDIUM 4.8
npm

CVE-2026-16728

undici vulnerable to downstream response desynchronization via retry interceptor

HIGH 7.4
npm

CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

HIGH 7.4
npm

CVE-2026-9697

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

MEDIUM 5.9
npm

CVE-2026-9678

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

MEDIUM 5.9
npm

CVE-2026-9679

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

LOW 3.7
npm

CVE-2026-11525

undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching

LOW 3.7
npm

CVE-2026-6733

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

MEDIUM 6.8
npm

CVE-2025-22150

Use of Insufficiently Random Values in undici

HIGH 7.5
npm

CVE-2026-6734

undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse

HIGH 7.5
npm

CVE-2026-1526

Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression

HIGH 7.5
npm

CVE-2026-2229

Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation

MEDIUM 5.9
npm

CVE-2026-2581

Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS

HIGH 7.5
npm

CVE-2026-1528

Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client

MEDIUM 4.6
npm

CVE-2026-1527

Undici has CRLF Injection in undici via `upgrade` option

MEDIUM 6.5
npm

CVE-2026-1525

Undici has an HTTP Request/Response Smuggling issue

MEDIUM 5.9
npm

CVE-2026-22036

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

LOW 3.1
npm

CVE-2025-47279

undici Denial of Service attack via bad certificate data

LOW 2.0
npm

CVE-2024-38372

Undici vulnerable to data leak when using response.arrayBuffer()

HIGH 7.5
npm

CVE-2026-12151

undici WebSocket client vulnerable to denial of service via fragment count bypass

HIGH 7.5
npm

CVE-2023-24807

Regular Expression Denial of Service in Headers

MEDIUM 6.5
npm

CVE-2024-24750

fetch(url) leads to a memory leak in undici

LOW 3.9
npm

CVE-2024-24758

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

MEDIUM 4.6
npm

CVE-2023-23936

CRLF Injection in Nodejs ‘undici’ via host

HIGH 7.7
npm

CVE-2022-32210

ProxyAgent vulnerable to MITM

HIGH 7.5
npm

CVE-2026-9675

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

LOW 3.7
npm

CVE-2022-31151

undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect

LOW 3.9
npm

CVE-2023-45143

Undici's cookie header not cleared on cross-origin redirect in fetch

LOW 2.6
npm

CVE-2024-30261

Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect

LOW 3.9
npm

CVE-2024-30260

Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

MEDIUM 5.3
npm

CVE-2022-35949

`undici.request` vulnerable to SSRF using absolute URL on `pathname`

MEDIUM 5.3
npm

CVE-2022-35948

Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type

MEDIUM 5.3
npm

CVE-2022-31150

undici before v5.8.0 vulnerable to CRLF injection in request headers

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes