MEDIUM 4.6 npm

CRLF Injection in Nodejs ‘undici’ via host

GHSA-5r9g-qh6m-jxff · BIT-node-2023-23936 · BIT-node-min-2023-23936 · CVE-2023-23936

Published · Modified

Description

Impact

undici library does not protect host HTTP header from CRLF injection vulnerabilities.

Patches

This issue was patched in Undici v5.19.1.

Workarounds

Sanitize the headers.host string before passing to undici.

References

Reported at https://hackerone.com/reports/1820955.

Credits

Thank you to Zhipeng Zhang (@timon8) for reporting this vulnerability.

Ready to move

Start Securing

Free, no credit card | First findings in minutes