LOW 3.1 npm

undici Denial of Service attack via bad certificate data

GHSA-cxrh-j4jr-qwg3 · CVE-2025-47279

Published · Modified

Description

Impact

Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.

Patches

This has been patched in https://github.com/nodejs/undici/pull/4088.

Workarounds

If a webhook fails, avoid keep calling it repeatedly.

References

Reported as: https://github.com/nodejs/undici/issues/3895

Ready to move

Start Securing

Free, no credit card | First findings in minutes