Vulnerabilities
Last updated 6 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression | Medium Risk 5.9 | 7 hours ago | 6 hours ago |
|
|
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives | Medium Risk 5.9 | 1 month ago | 19 days ago |
|
|
undici vulnerable to CRLF Injection via blob-like body 'type' property | Medium Risk 4.2 | 1 month ago | 19 days ago |
|
|
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields | Medium Risk 4.8 | 1 month ago | 19 days ago |
|
|
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives | High Risk 7.4 | 1 month ago | 19 days ago |
|
|
undici vulnerable to downstream response desynchronization via retry interceptor | Medium Risk 4.8 | 1 month ago | 19 days ago |
|
|
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding | Medium Risk 5.9 | 3 months ago | 19 days ago |
|
|
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass | Medium Risk 5.9 | 3 months ago | 19 days ago |
|
|
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | High Risk 7.4 | 3 months ago | 19 days ago |
|
|
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching | Low Risk 3.7 | 3 months ago | 19 days ago |
|
|
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse | Low Risk 3.7 | 3 months ago | 19 days ago |
|
|
Use of Insufficiently Random Values in undici | Medium Risk 6.8 | 1 year ago | 19 days ago |
|
|
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse | High Risk 7.5 | 3 months ago | 19 days ago |
|
|
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation | High Risk 7.5 | 6 months ago | 19 days ago |
|
|
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression | High Risk 7.5 | 6 months ago | 19 days ago |
|
|
Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS | Medium Risk 5.9 | 6 months ago | 19 days ago |
|
|
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client | High Risk 7.5 | 6 months ago | 19 days ago |
|
|
Undici has CRLF Injection in undici via `upgrade` option | Medium Risk 4.6 | 6 months ago | 19 days ago |
|
|
Undici has an HTTP Request/Response Smuggling issue | Medium Risk 6.5 | 6 months ago | 19 days ago |
|
|
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion | Medium Risk 5.9 | 8 months ago | 19 days ago |
|
|
undici Denial of Service attack via bad certificate data | Low Risk 3.1 | 1 year ago | 19 days ago |
|
|
Undici vulnerable to data leak when using response.arrayBuffer() | Low Risk 2.0 | 2 years ago | 19 days ago |
|
|
undici WebSocket client vulnerable to denial of service via fragment count bypass | High Risk 7.5 | 3 months ago | 19 days ago |
|
|
Regular Expression Denial of Service in Headers | High Risk 7.5 | 3 years ago | 19 days ago |
|
|
fetch(url) leads to a memory leak in undici | Medium Risk 6.5 | 2 years ago | 19 days ago |
|
|
Undici proxy-authorization header not cleared on cross-origin redirect in fetch | Low Risk 3.9 | 2 years ago | 19 days ago |
|
|
CRLF Injection in Nodejs ‘undici’ via host | Medium Risk 4.6 | 3 years ago | 19 days ago |
|
|
ProxyAgent vulnerable to MITM | High Risk 7.7 | 4 years ago | 2 months ago |
|
|
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass | High Risk 7.5 | 3 months ago | 3 months ago |
|
|
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect | Low Risk 3.7 | 4 years ago | 7 months ago |
|
|
Undici's cookie header not cleared on cross-origin redirect in fetch | Low Risk 3.9 | 2 years ago | 7 months ago |
|
|
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect | Low Risk 2.6 | 2 years ago | 10 months ago |
|
|
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline | Low Risk 3.9 | 2 years ago | 10 months ago |
|
|
`undici.request` vulnerable to SSRF using absolute URL on `pathname` | Medium Risk 5.3 | 4 years ago | 2 years ago |
|
|
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type | Medium Risk 5.3 | 4 years ago | 2 years ago |
|
|
undici before v5.8.0 vulnerable to CRLF injection in request headers | Medium Risk 5.3 | 4 years ago | 2 years ago |
Page 1