CVEs we hold for Undici
Records whose assigning authority named Undici as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9697undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgentundici
CVE-2026-9678undici vulnerable to cross-user information disclosure via shared cache whitespace bypassundici
CVE-2026-9675undici WebSocket client vulnerable to denial of service via cumulative fragment bypassundici
CVE-2026-85152undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptorsundici
CVE-2026-85024undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompressionundici
CVE-2026-84961undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPoolundici
CVE-2026-84947undici vulnerable to response truncation via oversized chunked responses in the dump interceptorundici
CVE-2026-84933undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared cachesundici
CVE-2026-84890undici vulnerable to Denial of Service via unbounded decompression of compressed responsesundici
CVE-2026-2581undici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads…undici
CVE-2026-2229undici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits Validationundici
CVE-2026-16729undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fieldsundici
CVE-2026-16728undici vulnerable to downstream response desynchronization via retry interceptorundici
CVE-2026-1528undici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the clientundici
CVE-2026-1526undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate Decompressionundici
CVE-2026-1525undici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')undici
CVE-2026-14643undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directivesundici
CVE-2026-13697undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesundici
CVE-2026-12151undici WebSocket client vulnerable to denial of service via fragment count bypassundici
CVE-2026-11525undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matchingundici
30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.