Pricing
Case studies
Login
Start trial
undici
Maintainer(s)
matteo.collina, +2
Latest version
N/A
Weekly downloads
105,989,707
npm
MIT
View project
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
46 patched
0 Mitigation rules
NPM: undici vulnerable to Denial of Service via orphaned RetryHandler response body
>= 7.11.0, < 7.29.1
1 hour ago
NPM: undici vulnerable to downstream response splitting via retry interceptor
< 6.28.1
1 hour ago
NPM: undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
>= 6.7.0, < 6.28.1
1 hour ago
NPM: undici vulnerable to Denial of Service via unbounded decompression of compressed responses
>= 7.15.0, < 7.29.1
2 hours ago
NPM: undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
>= 7.0.0, < 7.29.1
2 hours ago
NPM: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
>= 7.1.0, < 7.29.1
2 hours ago
NPM: undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
>= 7.24.1, < 7.29.1
2 hours ago
NPM: undici vulnerable to caching and replay of unsafe HTTP method responses
>= 7.0.0, < 7.29.1
2 hours ago
NPM: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
>= 8.10.0, < 8.10.2
2 hours ago
NPM: undici vulnerable to Denial of Service via WebSocketStream unclean close
>= 7.0.0, < 7.29.1
2 hours ago
NPM: undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
>= 6.25.0, < 6.28.1
22 hours ago
NPM: undici vulnerable to CRLF Injection via blob-like body 'type' property
< 6.28.0
03/08/2026
NPM: undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
>= 7.0.0, < 7.29.0
03/08/2026
NPM: undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
< 6.28.0
03/08/2026
NPM: undici vulnerable to downstream response desynchronization via retry interceptor
< 6.28.0
03/08/2026
NPM: undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
>= 7.0.0, < 7.29.0
03/08/2026
NPM: undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
< 6.27.0
19/06/2026
NPM: undici WebSocket client vulnerable to denial of service via fragment count bypass
< 6.27.0
19/06/2026
NPM: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
< 6.27.0
19/06/2026
NPM: undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
>= 7.23.0, < 7.28.0
19/06/2026
NPM: undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
< 6.27.0
19/06/2026
NPM: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
>= 7.23.0, < 7.28.0
18/06/2026
NPM: undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
>= 7.0.0, < 7.28.0
18/06/2026
NPM: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
>= 8.0.0, < 8.5.0
18/06/2026
NPM: Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
< 6.24.0
13/03/2026
NPM: Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
< 6.24.0
13/03/2026
NPM: Undici has CRLF Injection in undici via `upgrade` option
< 6.24.0
13/03/2026
NPM: Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
>= 7.17.0, < 7.24.0
13/03/2026
NPM: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
>= 6.0.0, < 6.24.0
13/03/2026
NPM: Undici has an HTTP Request/Response Smuggling issue
< 6.24.0
13/03/2026
NPM: Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
< 6.23.0
14/01/2026
NPM: undici Denial of Service attack via bad certificate data
< 5.29.0
15/05/2025
NPM: Use of Insufficiently Random Values in undici
>= 4.5.0, < 5.28.5
21/01/2025
NPM: Undici vulnerable to data leak when using response.arrayBuffer()
>= 6.14.0, < 6.19.2
09/07/2024
NPM: Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
< 5.28.4
04/04/2024
NPM: Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
< 5.28.4
04/04/2024
NPM: Undici proxy-authorization header not cleared on cross-origin redirect in fetch
<= 5.28.2
16/02/2024
NPM: fetch(url) leads to a memory leak in undici
>= 6.0.0, <= 6.6.0
16/02/2024
NPM: Undici's cookie header not cleared on cross-origin redirect in fetch
< 5.26.2
16/10/2023
NPM: CRLF Injection in Nodejs ‘undici’ via host
>= 2.0.0, < 5.19.1
16/02/2023
NPM: Regular Expression Denial of Service in Headers
< 5.19.1
16/02/2023
NPM: Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
<= 5.8.1
18/08/2022
NPM: `undici.request` vulnerable to SSRF using absolute URL on `pathname`
<= 5.8.1
18/08/2022
NPM: undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
< 5.8.0
21/07/2022
NPM: undici before v5.8.0 vulnerable to CRLF injection in request headers
< 5.8.0
21/07/2022
NPM: ProxyAgent vulnerable to MITM
>= 4.8.2, <= 5.5.0
17/06/2022