LOW 3.1 npm
undici Denial of Service attack via bad certificate data
GHSA-cxrh-j4jr-qwg3 · CVE-2025-47279
Published · Modified
Description
Impact
Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.
Patches
This has been patched in https://github.com/nodejs/undici/pull/4088.
Workarounds
If a webhook fails, avoid keep calling it repeatedly.
References
Reported as: https://github.com/nodejs/undici/issues/3895
References
- WEB https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-47279
- WEB https://github.com/nodejs/undici/issues/3895
- WEB https://github.com/nodejs/undici/pull/4088
- WEB https://github.com/nodejs/undici/commit/f317618ec28753a4218beccea048bcf89c36db25
- PACKAGE https://github.com/nodejs/undici
Ready to move
Start Securing
Free, no credit card | First findings in minutes