vendor

nodejs

14 thingsrelated by NVD

Its products

undici 14

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation
CVE-2026-85152
Severity high
undici: undici: Denial of Service via unhandled error in WebSocket permessage-deflate decompression
CVE-2026-85024
Severity medium
undici: undici: Denial of Service via WebSocketStream unclean close
CVE-2026-85014
Severity high
undici: undici: Integrity failure due to caching of unsafe HTTP method responses
CVE-2026-85008
Severity medium
undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options
CVE-2026-84961
Severity critical
undici: Undici: Response truncation and connection termination
CVE-2026-84947
Severity medium
undici: undici: Cross-user cookie disclosure via Set-Cookie caching
CVE-2026-84933
Severity high
undici: undici: Denial of Service via unbounded decompression of compressed responses
CVE-2026-84890
Severity medium
undici: undici: Denial of Service via unrequested WebSocket subprotocol
CVE-2026-19534
Severity high
undici: undici: HTTP response splitting via retry interceptor
CVE-2026-18540
Severity low
undici: undici: Denial of Service due to orphaned response body in retry handler
CVE-2026-18149
Severity medium
undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames
CVE-2026-12151
Severity high
undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy
CVE-2026-9697
Severity high
undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing
CVE-2026-6734
Severity high