Threat Advisory

undici Vulnerabilities Trigger Application Crashes and Information Leakage

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting undici, a library used for building HTTP clients and servers, including its WebSocketStream API, have been identified. The vulnerabilities may allow Denial of Service (DoS) attacks and information disclosure through cache poisoning.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting undici, a library used for building HTTP clients and servers, including its WebSocketStream API, have been identified. The vulnerabilities may allow Denial of Service (DoS) attacks and information disclosure through cache poisoning.[emaillocker id="1283"]

CVE-2026-85014 (CVSS 5.9 — Medium): undici's WebSocketStream crashes the client process when a WebSocket connection is closed abruptly without a close handshake, causing abort() to trigger an unhandledRejection in WHATWG Streams. A malicious or compromised WebSocket server can crash a client with a single unclean connection teardown.

CVE-2026-85152 (CVSS 7.4 — High): undici is vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors.cache() and interceptors.deduplicate(). An attacker who controls the response from one origin can have that response returned for a request to a different trusted origin when the method, path, and relevant headers match.

CVE-2026-84961 (CVSS 7.4 — High): undici is vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool when using a JSON-based deep clone with Client, Pool, Agent, and RoundRobinPool, causing checkServerIdentity to be dropped. This allows an attacker to bypass TLS certificate validation and establish a connection without proper authentication.

CVE-2026-84933 (CVSS 6.5 — Medium): It is a vulnerability in undici's interceptors.cache() that allows shared caches to store and re-serve Set-Cookie headers, exposing cookies across callers and enabling cookie injection.

CVE-2026-84890 (CVSS 5.9 — Medium): It is a vulnerability in undici's interceptors.decompress() that allows malicious compressed responses to cause excessive memory consumption, potentially crashing or making the Node.js process unresponsive.

CVE-2026-19534 (CVSS 7.5 — High): It is a vulnerability in undici's WebSocket client where an unsolicited Sec-WebSocket-Protocol header violates RFC 6455 section 4.1 and triggers an uncaught TypeError without try/catch, causing Node.js process termination.

CVE-2026-18149 (CVSS 5.9 — Medium): It is a vulnerability in undici's RetryHandler that leaves the original response.body pending after a truncated response followed by a non-retryable response, causing response.body.text() to hang and allowing pending promises and streams to accumulate and cause denial of service.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-rx4f-c7p8-82vq
https://github.com/advisories/GHSA-vp8m-p9jh-q5pm
https://github.com/advisories/GHSA-w293-vg96-wgc3
https://github.com/advisories/GHSA-2jfj-6hjv-fm6j
https://github.com/advisories/GHSA-3xpg-4rpp-hhhm
https://github.com/advisories/GHSA-rfgv-xxqx-mfg5
https://github.com/advisories/GHSA-pmjh-fq2x-6v4x

[/emaillocker]
crossmenu