Vulnerabilities

Last updated 5 hours ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
undici undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression Medium Risk 5.9 6 hours ago 6 hours ago
undici undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives Medium Risk 5.9 1 month ago 19 days ago
undici undici vulnerable to CRLF Injection via blob-like body 'type' property Medium Risk 4.2 1 month ago 19 days ago
undici undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields Medium Risk 4.8 1 month ago 19 days ago
undici undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives High Risk 7.4 1 month ago 19 days ago
undici undici vulnerable to downstream response desynchronization via retry interceptor Medium Risk 4.8 1 month ago 19 days ago
undici undici vulnerable to HTTP header injection via Set-Cookie percent-decoding Medium Risk 5.9 3 months ago 19 days ago
undici undici vulnerable to cross-user information disclosure via shared cache whitespace bypass Medium Risk 5.9 3 months ago 19 days ago
undici undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent High Risk 7.4 3 months ago 19 days ago
undici undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching Low Risk 3.7 3 months ago 19 days ago
undici undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse Low Risk 3.7 3 months ago 19 days ago
undici Use of Insufficiently Random Values in undici Medium Risk 6.8 1 year ago 19 days ago
undici undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse High Risk 7.5 3 months ago 19 days ago
undici Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation High Risk 7.5 6 months ago 19 days ago
undici Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression High Risk 7.5 6 months ago 19 days ago
undici Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS Medium Risk 5.9 6 months ago 19 days ago
undici Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client High Risk 7.5 6 months ago 19 days ago
undici Undici has CRLF Injection in undici via `upgrade` option Medium Risk 4.6 6 months ago 19 days ago
undici Undici has an HTTP Request/Response Smuggling issue Medium Risk 6.5 6 months ago 19 days ago
undici Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion Medium Risk 5.9 8 months ago 19 days ago
undici undici Denial of Service attack via bad certificate data Low Risk 3.1 1 year ago 19 days ago
undici Undici vulnerable to data leak when using response.arrayBuffer() Low Risk 2.0 2 years ago 19 days ago
undici undici WebSocket client vulnerable to denial of service via fragment count bypass High Risk 7.5 3 months ago 19 days ago
undici Regular Expression Denial of Service in Headers High Risk 7.5 3 years ago 19 days ago
undici fetch(url) leads to a memory leak in undici Medium Risk 6.5 2 years ago 19 days ago
undici Undici proxy-authorization header not cleared on cross-origin redirect in fetch Low Risk 3.9 2 years ago 19 days ago
undici CRLF Injection in Nodejs ‘undici’ via host Medium Risk 4.6 3 years ago 19 days ago
undici ProxyAgent vulnerable to MITM High Risk 7.7 4 years ago 2 months ago
undici undici WebSocket client vulnerable to denial of service via cumulative fragment bypass High Risk 7.5 3 months ago 3 months ago
undici undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect Low Risk 3.7 4 years ago 7 months ago
undici Undici's cookie header not cleared on cross-origin redirect in fetch Low Risk 3.9 2 years ago 7 months ago
undici Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect Low Risk 2.6 2 years ago 10 months ago
undici Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline Low Risk 3.9 2 years ago 10 months ago
undici `undici.request` vulnerable to SSRF using absolute URL on `pathname` Medium Risk 5.3 4 years ago 2 years ago
undici Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type Medium Risk 5.3 4 years ago 2 years ago
undici undici before v5.8.0 vulnerable to CRLF injection in request headers Medium Risk 5.3 4 years ago 2 years ago