MEDIUM 4.6 npm

CRLF Injection in Nodejs ‘undici’ via host

GHSA-5r9g-qh6m-jxff · BIT-node-2023-23936 · BIT-node-min-2023-23936 · CVE-2023-23936

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

undici library does not protect host HTTP header from CRLF injection vulnerabilities.

Patches

This issue was patched in Undici v5.19.1.

Workarounds

Sanitize the headers.host string before passing to undici.

References

Reported at https://hackerone.com/reports/1820955.

Credits

Thank you to Zhipeng Zhang (@timon8) for reporting this vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes