undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options
cve CVE-2026-84961 3 sources, 3 claims · Watch
Red Hat writes:
undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options the claim
undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options the claim
- Severity they disagree
- high GitHub advisoriesCRITICAL NVDimportant Red Hat
- CVSS they disagree
- 7.4 GitHub advisories9.1 NVD7.4 Red Hat
- Fixed in
- 7.29.1, 8.10.2 NVD
- Vendor
- undici NVD
- Product
- undici NVD
- CWE
- CWE-295 GitHub advisoriesCWE-295 NVDCWE-295 Red Hat
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Why the CVSS differs
| Metric | NVD | Red Hat |
|---|---|---|
| Attack vector AV | network N | network N |
| Attack complexity AC | low L | high H |
| Privileges required PR | none N | none N |
| User interaction UI | none N | none N |
| Scope S | unchanged U | unchanged U |
| Confidentiality C | high H | high H |
| Integrity I | high H | high H |
| Availability A | none N | none N |
Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.
Timeline
| 2026-09-04 | first spoke of it: undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2. | NVD |
| 2026-09-04 | first spoke of it: undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options | Red Hat |
| 2026-09-29 | first spoke of it: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool | GitHub advisories |
What it is to other things
| affects | nodejs/undici NVD |
| made_by | nodejs NVD |
In words only, so not counted until a person confirms one:
| made_by | undiciNVD says “undici” |
| affects | undici/undiciNVD says “undici · undici” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss conflict | GitHub advisories | 7.4receipt
What the source handed over{
"credits": [
{
"type": "reporter",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/2505339?v=4",
"events_url": "https://api.github.com/users/MegaManSec/events{/privacy}",
"followers_url": "https://api.github.com/users/MegaManSec/followers",
"following_url": "https://api.github.com/users/MegaManSec/following{/other_user}",
"gists_url": "https://api.github.com/users/MegaManSec/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/MegaManSec",
"id": 2505339,
"login": "MegaManSec",
"node_id": "MDQ6VXNlcjI1MDUzMzk=",
"organizations_url": "https://api.github.com/users/MegaManSec/orgs",
"received_events_url": "https://api.github.com/users/MegaManSec/received_events",
"repos_url": "https://api.github.com/users/MegaManSec/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/MegaManSec/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/MegaManSec/subscriptions",
"type": "User",
"url": "https://api.github.com/users/MegaManSec",
"user_view_type": "public"
}
},
{
"type": "remediation_developer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/52195?v=4",
"events_url": "https://api.github.com/users/mcollina/events{/privacy}",
"followers_url": "https://api.github.com/users/mcollina/followers",
"following_url": "https://api.github.com/users/mcollina/following{/other_user}",
"gists_url": "https://api.github.com/users/mcollina/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/mcollina",
"id": 52195,
"login": "mcollina",
"node_id": "MDQ6VXNlcjUyMTk1",
"organizations_url": "https://api.github.com/users/mcollina/orgs",
"received_events_url": "https://api.github.com/users/mcollina/received_events",
"repos_url": "https://api.github.com/users/mcollina/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/mcollina/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/mcollina/subscriptions",
"type": "User",
"url": "https://api.github.com/users/mcollina",
"user_view_type": "public"
}
},
{
"type": "remediation_reviewer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/5110813?v=4",
"events_url": "https://api.github.com/users/UlisesGascon/events{/privacy}",
"followers_url": "https://api.github.com/users/UlisesGascon/followers",
"following_url": "https://api.github.com/users/UlisesGascon/following{/other_user}",
"gists_url": "https://api.github.com/users/UlisesGascon/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/UlisesGascon",
"id": 5110813,
"login": "UlisesGascon",
"node_id": "MDQ6VXNlcjUxMTA4MTM=",
"organizations_url": "https://api.github.com/users/UlisesGascon/orgs",
"received_events_url": "https://api.github.com/users/UlisesGascon/received_events",
"repos_url": "https://api.github.com/users/UlisesGascon/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/UlisesGascon/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/UlisesGascon/subscriptions",
"type": "User",
"url": "https://api.github.com/users/UlisesGascon",
"user_view_type": "public"
}
}
],
"cve_id": "CVE-2026-84961",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-295",
"name": "Improper Certificate Validation"
}
],
"description": "### Impact\n\nundici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity` callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom `checkServerIdentity` was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through `BalancedPool`. `Client`, `Pool`, `Agent`, and `RoundRobinPool` destructure `connect`/`tls` before the clone and are not affected. Only applications that use `BalancedPool` with a function-valued `connect`/`tls` option (such as a custom `checkServerIdentity` or connector) are affected.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. `BalancedPool` now preserves the `connect` and `tls` options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.\n\n### Workarounds\n\nUse `Client`, `Pool`, or `Agent` instead of `BalancedPool` for connections that rely on a custom `checkServerIdentity` or connector, until upgraded.",
"epss": {
"percentage": 0.00146,
"percentile": 0.03277
},
"ghsa_id": "GHSA-w293-vg96-wgc3",
"github_reviewed_at": "2026-09-29T18:17:15Z",
"html_url": "https://github.com/advisories/GHSA-w293-vg96-wgc3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-w293-vg96-wgc3"
},
{
"type": "CVE",
"value": "CVE-2026-84961"
}
],
"nvd_published_at": "2026-09-04T17:17:02Z",
"published_at": "2026-09-29T18:17:15Z",
"references": [
"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-84961",
"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390",
"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96",
"https://cna.openjsf.org/security-advisories.html",
"https://github.com/nodejs/undici/releases/tag/v7.29.1",
"https://github.com/nodejs/undici/releases/tag/v8.10.2",
"https://github.com/advisories/GHSA-w293-vg96-wgc3"
],
"repository_advisory_url": "https://api.github.com/repos/nodejs/undici/security-advisories/GHSA-w293-vg96-wgc3",
"severity": "high",
"source_code_location": "https://github.com/nodejs/undici",
"summary": "undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool",
"type": "reviewed",
"updated_at": "2026-09-29T18:17:16Z",
"url": "https://api.github.com/advisories/GHSA-w293-vg96-wgc3",
"vulnerabilities": [
{
"first_patched_version": "7.29.1",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 7.24.1, < 7.29.1"
},
{
"first_patched_version": "8.10.2",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 8.0.0, < 8.10.2"
}
],
"withdrawn_at": null
} | — | ||||
| CVSS cvss conflict | NVD | 9.1receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss conflict | Red Hat | 7.4receipt
What the source handed over{
"CVE": "CVE-2026-84961",
"CWE": "CWE-295",
"advisories": [
"RHSA-2026:74609",
"RHSA-2026:74085",
"RHSA-2026:73838",
"RHSA-2026:69248",
"RHSA-2026:73428",
"RHSA-2026:54438",
"RHSA-2026:66008",
"RHSA-2026:66605"
],
"affected_packages": [
"cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525",
"nodejs:24-8100020260921144227.6d880403",
"cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528",
"cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526",
"nodejs:24-9080020260921144317.rhel9",
"cluster-observability-operator/logging-console-plugin-pf4-rhel9:1790854525",
"nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1",
"nodejs26-main-11.19.1-1.26.8.2.0.1.hum1",
"nodejs24-1:24.21.0-1.el10_2",
"grafana12-4-main-12.4.10-0.2.hum1",
"rhdh/rhdh-hub-rhel9:1789554285"
],
"bugzilla": "2528735",
"bugzilla_description": "undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-04T16:47:55Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84961.json",
"severity": "important"
} | — | ||||
| CVSS vector cvss_vector not compared | NVD | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:Nreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector not compared | Red Hat | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:Nreceipt
What the source handed over{
"CVE": "CVE-2026-84961",
"CWE": "CWE-295",
"advisories": [
"RHSA-2026:74609",
"RHSA-2026:74085",
"RHSA-2026:73838",
"RHSA-2026:69248",
"RHSA-2026:73428",
"RHSA-2026:54438",
"RHSA-2026:66008",
"RHSA-2026:66605"
],
"affected_packages": [
"cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525",
"nodejs:24-8100020260921144227.6d880403",
"cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528",
"cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526",
"nodejs:24-9080020260921144317.rhel9",
"cluster-observability-operator/logging-console-plugin-pf4-rhel9:1790854525",
"nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1",
"nodejs26-main-11.19.1-1.26.8.2.0.1.hum1",
"nodejs24-1:24.21.0-1.el10_2",
"grafana12-4-main-12.4.10-0.2.hum1",
"rhdh/rhdh-hub-rhel9:1789554285"
],
"bugzilla": "2528735",
"bugzilla_description": "undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-04T16:47:55Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84961.json",
"severity": "important"
} | — | ||||
| CWE cwe | GitHub advisories | CWE-295receipt
What the source handed over{
"credits": [
{
"type": "reporter",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/2505339?v=4",
"events_url": "https://api.github.com/users/MegaManSec/events{/privacy}",
"followers_url": "https://api.github.com/users/MegaManSec/followers",
"following_url": "https://api.github.com/users/MegaManSec/following{/other_user}",
"gists_url": "https://api.github.com/users/MegaManSec/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/MegaManSec",
"id": 2505339,
"login": "MegaManSec",
"node_id": "MDQ6VXNlcjI1MDUzMzk=",
"organizations_url": "https://api.github.com/users/MegaManSec/orgs",
"received_events_url": "https://api.github.com/users/MegaManSec/received_events",
"repos_url": "https://api.github.com/users/MegaManSec/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/MegaManSec/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/MegaManSec/subscriptions",
"type": "User",
"url": "https://api.github.com/users/MegaManSec",
"user_view_type": "public"
}
},
{
"type": "remediation_developer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/52195?v=4",
"events_url": "https://api.github.com/users/mcollina/events{/privacy}",
"followers_url": "https://api.github.com/users/mcollina/followers",
"following_url": "https://api.github.com/users/mcollina/following{/other_user}",
"gists_url": "https://api.github.com/users/mcollina/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/mcollina",
"id": 52195,
"login": "mcollina",
"node_id": "MDQ6VXNlcjUyMTk1",
"organizations_url": "https://api.github.com/users/mcollina/orgs",
"received_events_url": "https://api.github.com/users/mcollina/received_events",
"repos_url": "https://api.github.com/users/mcollina/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/mcollina/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/mcollina/subscriptions",
"type": "User",
"url": "https://api.github.com/users/mcollina",
"user_view_type": "public"
}
},
{
"type": "remediation_reviewer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/5110813?v=4",
"events_url": "https://api.github.com/users/UlisesGascon/events{/privacy}",
"followers_url": "https://api.github.com/users/UlisesGascon/followers",
"following_url": "https://api.github.com/users/UlisesGascon/following{/other_user}",
"gists_url": "https://api.github.com/users/UlisesGascon/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/UlisesGascon",
"id": 5110813,
"login": "UlisesGascon",
"node_id": "MDQ6VXNlcjUxMTA4MTM=",
"organizations_url": "https://api.github.com/users/UlisesGascon/orgs",
"received_events_url": "https://api.github.com/users/UlisesGascon/received_events",
"repos_url": "https://api.github.com/users/UlisesGascon/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/UlisesGascon/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/UlisesGascon/subscriptions",
"type": "User",
"url": "https://api.github.com/users/UlisesGascon",
"user_view_type": "public"
}
}
],
"cve_id": "CVE-2026-84961",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-295",
"name": "Improper Certificate Validation"
}
],
"description": "### Impact\n\nundici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity` callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom `checkServerIdentity` was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through `BalancedPool`. `Client`, `Pool`, `Agent`, and `RoundRobinPool` destructure `connect`/`tls` before the clone and are not affected. Only applications that use `BalancedPool` with a function-valued `connect`/`tls` option (such as a custom `checkServerIdentity` or connector) are affected.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. `BalancedPool` now preserves the `connect` and `tls` options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.\n\n### Workarounds\n\nUse `Client`, `Pool`, or `Agent` instead of `BalancedPool` for connections that rely on a custom `checkServerIdentity` or connector, until upgraded.",
"epss": {
"percentage": 0.00146,
"percentile": 0.03277
},
"ghsa_id": "GHSA-w293-vg96-wgc3",
"github_reviewed_at": "2026-09-29T18:17:15Z",
"html_url": "https://github.com/advisories/GHSA-w293-vg96-wgc3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-w293-vg96-wgc3"
},
{
"type": "CVE",
"value": "CVE-2026-84961"
}
],
"nvd_published_at": "2026-09-04T17:17:02Z",
"published_at": "2026-09-29T18:17:15Z",
"references": [
"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-84961",
"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390",
"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96",
"https://cna.openjsf.org/security-advisories.html",
"https://github.com/nodejs/undici/releases/tag/v7.29.1",
"https://github.com/nodejs/undici/releases/tag/v8.10.2",
"https://github.com/advisories/GHSA-w293-vg96-wgc3"
],
"repository_advisory_url": "https://api.github.com/repos/nodejs/undici/security-advisories/GHSA-w293-vg96-wgc3",
"severity": "high",
"source_code_location": "https://github.com/nodejs/undici",
"summary": "undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool",
"type": "reviewed",
"updated_at": "2026-09-29T18:17:16Z",
"url": "https://api.github.com/advisories/GHSA-w293-vg96-wgc3",
"vulnerabilities": [
{
"first_patched_version": "7.29.1",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 7.24.1, < 7.29.1"
},
{
"first_patched_version": "8.10.2",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 8.0.0, < 8.10.2"
}
],
"withdrawn_at": null
} | — | ||||
| CWE cwe | NVD | CWE-295receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | Red Hat | CWE-295receipt
What the source handed over{
"CVE": "CVE-2026-84961",
"CWE": "CWE-295",
"advisories": [
"RHSA-2026:74609",
"RHSA-2026:74085",
"RHSA-2026:73838",
"RHSA-2026:69248",
"RHSA-2026:73428",
"RHSA-2026:54438",
"RHSA-2026:66008",
"RHSA-2026:66605"
],
"affected_packages": [
"cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525",
"nodejs:24-8100020260921144227.6d880403",
"cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528",
"cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526",
"nodejs:24-9080020260921144317.rhel9",
"cluster-observability-operator/logging-console-plugin-pf4-rhel9:1790854525",
"nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1",
"nodejs26-main-11.19.1-1.26.8.2.0.1.hum1",
"nodejs24-1:24.21.0-1.el10_2",
"grafana12-4-main-12.4.10-0.2.hum1",
"rhdh/rhdh-hub-rhel9:1789554285"
],
"bugzilla": "2528735",
"bugzilla_description": "undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-04T16:47:55Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84961.json",
"severity": "important"
} | — | ||||
| Ecosystem ecosystem | GitHub advisories | npm, npmreceipt
What the source handed over{
"credits": [
{
"type": "reporter",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/2505339?v=4",
"events_url": "https://api.github.com/users/MegaManSec/events{/privacy}",
"followers_url": "https://api.github.com/users/MegaManSec/followers",
"following_url": "https://api.github.com/users/MegaManSec/following{/other_user}",
"gists_url": "https://api.github.com/users/MegaManSec/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/MegaManSec",
"id": 2505339,
"login": "MegaManSec",
"node_id": "MDQ6VXNlcjI1MDUzMzk=",
"organizations_url": "https://api.github.com/users/MegaManSec/orgs",
"received_events_url": "https://api.github.com/users/MegaManSec/received_events",
"repos_url": "https://api.github.com/users/MegaManSec/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/MegaManSec/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/MegaManSec/subscriptions",
"type": "User",
"url": "https://api.github.com/users/MegaManSec",
"user_view_type": "public"
}
},
{
"type": "remediation_developer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/52195?v=4",
"events_url": "https://api.github.com/users/mcollina/events{/privacy}",
"followers_url": "https://api.github.com/users/mcollina/followers",
"following_url": "https://api.github.com/users/mcollina/following{/other_user}",
"gists_url": "https://api.github.com/users/mcollina/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/mcollina",
"id": 52195,
"login": "mcollina",
"node_id": "MDQ6VXNlcjUyMTk1",
"organizations_url": "https://api.github.com/users/mcollina/orgs",
"received_events_url": "https://api.github.com/users/mcollina/received_events",
"repos_url": "https://api.github.com/users/mcollina/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/mcollina/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/mcollina/subscriptions",
"type": "User",
"url": "https://api.github.com/users/mcollina",
"user_view_type": "public"
}
},
{
"type": "remediation_reviewer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/5110813?v=4",
"events_url": "https://api.github.com/users/UlisesGascon/events{/privacy}",
"followers_url": "https://api.github.com/users/UlisesGascon/followers",
"following_url": "https://api.github.com/users/UlisesGascon/following{/other_user}",
"gists_url": "https://api.github.com/users/UlisesGascon/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/UlisesGascon",
"id": 5110813,
"login": "UlisesGascon",
"node_id": "MDQ6VXNlcjUxMTA4MTM=",
"organizations_url": "https://api.github.com/users/UlisesGascon/orgs",
"received_events_url": "https://api.github.com/users/UlisesGascon/received_events",
"repos_url": "https://api.github.com/users/UlisesGascon/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/UlisesGascon/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/UlisesGascon/subscriptions",
"type": "User",
"url": "https://api.github.com/users/UlisesGascon",
"user_view_type": "public"
}
}
],
"cve_id": "CVE-2026-84961",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-295",
"name": "Improper Certificate Validation"
}
],
"description": "### Impact\n\nundici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity` callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom `checkServerIdentity` was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through `BalancedPool`. `Client`, `Pool`, `Agent`, and `RoundRobinPool` destructure `connect`/`tls` before the clone and are not affected. Only applications that use `BalancedPool` with a function-valued `connect`/`tls` option (such as a custom `checkServerIdentity` or connector) are affected.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. `BalancedPool` now preserves the `connect` and `tls` options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.\n\n### Workarounds\n\nUse `Client`, `Pool`, or `Agent` instead of `BalancedPool` for connections that rely on a custom `checkServerIdentity` or connector, until upgraded.",
"epss": {
"percentage": 0.00146,
"percentile": 0.03277
},
"ghsa_id": "GHSA-w293-vg96-wgc3",
"github_reviewed_at": "2026-09-29T18:17:15Z",
"html_url": "https://github.com/advisories/GHSA-w293-vg96-wgc3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-w293-vg96-wgc3"
},
{
"type": "CVE",
"value": "CVE-2026-84961"
}
],
"nvd_published_at": "2026-09-04T17:17:02Z",
"published_at": "2026-09-29T18:17:15Z",
"references": [
"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-84961",
"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390",
"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96",
"https://cna.openjsf.org/security-advisories.html",
"https://github.com/nodejs/undici/releases/tag/v7.29.1",
"https://github.com/nodejs/undici/releases/tag/v8.10.2",
"https://github.com/advisories/GHSA-w293-vg96-wgc3"
],
"repository_advisory_url": "https://api.github.com/repos/nodejs/undici/security-advisories/GHSA-w293-vg96-wgc3",
"severity": "high",
"source_code_location": "https://github.com/nodejs/undici",
"summary": "undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool",
"type": "reviewed",
"updated_at": "2026-09-29T18:17:16Z",
"url": "https://api.github.com/advisories/GHSA-w293-vg96-wgc3",
"vulnerabilities": [
{
"first_patched_version": "7.29.1",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 7.24.1, < 7.29.1"
},
{
"first_patched_version": "8.10.2",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 8.0.0, < 8.10.2"
}
],
"withdrawn_at": null
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| Fixed in fixed_in | NVD | 7.29.1, 8.10.2receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| Packages packages | Red Hat | cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525, nodejs:24-8100020260921144227.6d880403, cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528, cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526, nodejs:24-9080020260921144317.rhel9, cluster-observability-operator/logging-console-plugin-pf4-rhel9:1790854525, nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1, nodejs26-main-11.19.1-1.26.8.2.0.1.hum1, nodejs24-1:24.21.0-1.el10_2, grafana12-4-main-12.4.10-0.2.hum1, rhdh/rhdh-hub-rhel9:1789554285receipt
What the source handed over{
"CVE": "CVE-2026-84961",
"CWE": "CWE-295",
"advisories": [
"RHSA-2026:74609",
"RHSA-2026:74085",
"RHSA-2026:73838",
"RHSA-2026:69248",
"RHSA-2026:73428",
"RHSA-2026:54438",
"RHSA-2026:66008",
"RHSA-2026:66605"
],
"affected_packages": [
"cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525",
"nodejs:24-8100020260921144227.6d880403",
"cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528",
"cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526",
"nodejs:24-9080020260921144317.rhel9",
"cluster-observability-operator/logging-console-plugin-pf4-rhel9:1790854525",
"nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1",
"nodejs26-main-11.19.1-1.26.8.2.0.1.hum1",
"nodejs24-1:24.21.0-1.el10_2",
"grafana12-4-main-12.4.10-0.2.hum1",
"rhdh/rhdh-hub-rhel9:1789554285"
],
"bugzilla": "2528735",
"bugzilla_description": "undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-04T16:47:55Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84961.json",
"severity": "important"
} | — | ||||
| Product product | NVD | undicireceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity conflict | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [
{
"type": "reporter",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/2505339?v=4",
"events_url": "https://api.github.com/users/MegaManSec/events{/privacy}",
"followers_url": "https://api.github.com/users/MegaManSec/followers",
"following_url": "https://api.github.com/users/MegaManSec/following{/other_user}",
"gists_url": "https://api.github.com/users/MegaManSec/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/MegaManSec",
"id": 2505339,
"login": "MegaManSec",
"node_id": "MDQ6VXNlcjI1MDUzMzk=",
"organizations_url": "https://api.github.com/users/MegaManSec/orgs",
"received_events_url": "https://api.github.com/users/MegaManSec/received_events",
"repos_url": "https://api.github.com/users/MegaManSec/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/MegaManSec/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/MegaManSec/subscriptions",
"type": "User",
"url": "https://api.github.com/users/MegaManSec",
"user_view_type": "public"
}
},
{
"type": "remediation_developer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/52195?v=4",
"events_url": "https://api.github.com/users/mcollina/events{/privacy}",
"followers_url": "https://api.github.com/users/mcollina/followers",
"following_url": "https://api.github.com/users/mcollina/following{/other_user}",
"gists_url": "https://api.github.com/users/mcollina/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/mcollina",
"id": 52195,
"login": "mcollina",
"node_id": "MDQ6VXNlcjUyMTk1",
"organizations_url": "https://api.github.com/users/mcollina/orgs",
"received_events_url": "https://api.github.com/users/mcollina/received_events",
"repos_url": "https://api.github.com/users/mcollina/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/mcollina/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/mcollina/subscriptions",
"type": "User",
"url": "https://api.github.com/users/mcollina",
"user_view_type": "public"
}
},
{
"type": "remediation_reviewer",
"user": {
"avatar_url": "https://avatars.githubusercontent.com/u/5110813?v=4",
"events_url": "https://api.github.com/users/UlisesGascon/events{/privacy}",
"followers_url": "https://api.github.com/users/UlisesGascon/followers",
"following_url": "https://api.github.com/users/UlisesGascon/following{/other_user}",
"gists_url": "https://api.github.com/users/UlisesGascon/gists{/gist_id}",
"gravatar_id": "",
"html_url": "https://github.com/UlisesGascon",
"id": 5110813,
"login": "UlisesGascon",
"node_id": "MDQ6VXNlcjUxMTA4MTM=",
"organizations_url": "https://api.github.com/users/UlisesGascon/orgs",
"received_events_url": "https://api.github.com/users/UlisesGascon/received_events",
"repos_url": "https://api.github.com/users/UlisesGascon/repos",
"site_admin": false,
"starred_url": "https://api.github.com/users/UlisesGascon/starred{/owner}{/repo}",
"subscriptions_url": "https://api.github.com/users/UlisesGascon/subscriptions",
"type": "User",
"url": "https://api.github.com/users/UlisesGascon",
"user_view_type": "public"
}
}
],
"cve_id": "CVE-2026-84961",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-295",
"name": "Improper Certificate Validation"
}
],
"description": "### Impact\n\nundici's `BalancedPool` passes its constructor options through a JSON-based deep clone (`JSON.parse(JSON.stringify(...))`) before forwarding them to each per-upstream `Pool`. JSON cannot represent functions, so a caller-supplied `connect` or `tls` option containing a `checkServerIdentity` callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom `checkServerIdentity` was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through `BalancedPool`. `Client`, `Pool`, `Agent`, and `RoundRobinPool` destructure `connect`/`tls` before the clone and are not affected. Only applications that use `BalancedPool` with a function-valued `connect`/`tls` option (such as a custom `checkServerIdentity` or connector) are affected.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. `BalancedPool` now preserves the `connect` and `tls` options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.\n\n### Workarounds\n\nUse `Client`, `Pool`, or `Agent` instead of `BalancedPool` for connections that rely on a custom `checkServerIdentity` or connector, until upgraded.",
"epss": {
"percentage": 0.00146,
"percentile": 0.03277
},
"ghsa_id": "GHSA-w293-vg96-wgc3",
"github_reviewed_at": "2026-09-29T18:17:15Z",
"html_url": "https://github.com/advisories/GHSA-w293-vg96-wgc3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-w293-vg96-wgc3"
},
{
"type": "CVE",
"value": "CVE-2026-84961"
}
],
"nvd_published_at": "2026-09-04T17:17:02Z",
"published_at": "2026-09-29T18:17:15Z",
"references": [
"https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3",
"https://nvd.nist.gov/vuln/detail/CVE-2026-84961",
"https://github.com/nodejs/undici/commit/8f5868fbdbc8f1146dfc1bcd1f2d117790141390",
"https://github.com/nodejs/undici/commit/f690157d728508652fef14673630c71515123e96",
"https://cna.openjsf.org/security-advisories.html",
"https://github.com/nodejs/undici/releases/tag/v7.29.1",
"https://github.com/nodejs/undici/releases/tag/v8.10.2",
"https://github.com/advisories/GHSA-w293-vg96-wgc3"
],
"repository_advisory_url": "https://api.github.com/repos/nodejs/undici/security-advisories/GHSA-w293-vg96-wgc3",
"severity": "high",
"source_code_location": "https://github.com/nodejs/undici",
"summary": "undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool",
"type": "reviewed",
"updated_at": "2026-09-29T18:17:16Z",
"url": "https://api.github.com/advisories/GHSA-w293-vg96-wgc3",
"vulnerabilities": [
{
"first_patched_version": "7.29.1",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 7.24.1, < 7.29.1"
},
{
"first_patched_version": "8.10.2",
"package": {
"ecosystem": "npm",
"name": "undici"
},
"vulnerable_functions": [],
"vulnerable_version_range": ">= 8.0.0, < 8.10.2"
}
],
"withdrawn_at": null
} | — | ||||
| Severity severity conflict | NVD | CRITICAL From the CVSS base score at 9.0 and above. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | critical | ||||
| Severity severity conflict | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2026-84961",
"CWE": "CWE-295",
"advisories": [
"RHSA-2026:74609",
"RHSA-2026:74085",
"RHSA-2026:73838",
"RHSA-2026:69248",
"RHSA-2026:73428",
"RHSA-2026:54438",
"RHSA-2026:66008",
"RHSA-2026:66605"
],
"affected_packages": [
"cluster-observability-operator/monitoring-console-plugin-rhel9:1790854525",
"nodejs:24-8100020260921144227.6d880403",
"cluster-observability-operator/monitoring-console-plugin-pf6-rhel9:1790854528",
"cluster-observability-operator/monitoring-console-plugin-pf5-rhel9:1790854526",
"nodejs:24-9080020260921144317.rhel9",
"cluster-observability-operator/logging-console-plugin-pf4-rhel9:1790854525",
"nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1",
"nodejs26-main-11.19.1-1.26.8.2.0.1.hum1",
"nodejs24-1:24.21.0-1.el10_2",
"grafana12-4-main-12.4.10-0.2.hum1",
"rhdh/rhdh-hub-rhel9:1789554285"
],
"bugzilla": "2528735",
"bugzilla_description": "undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options",
"cvss3_score": "7.4",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-09-04T16:47:55Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-84961.json",
"severity": "important"
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | total The attacker gains full control of the component, or all of its information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | undicireceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.24.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "14C3FEF7-6460-4986-8FEB-A9F8540F14BA",
"versionEndExcluding": "7.29.1",
"versionStartIncluding": "7.24.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "848B6624-1708-4BF8-B9D7-8F34343D244B",
"versionEndExcluding": "8.10.2",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"id": "CVE-2026-84961",
"lastModified": "2026-09-15T14:29:35.253",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-84961",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:35:57.858790Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-04T17:17:02.227",
"references": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Third Party Advisory"
],
"url": "https://cna.openjsf.org/security-advisories.html"
},
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-295"
}
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"type": "Secondary"
}
]
}
} | — |