CVE-2026-1525 describes a critical vulnerability in Node.js undici, allowing duplicate HTTP Content-Length headers with case-variant names, which results in malformed HTTP/1.1 requests. This impacts applications using undici's low-level APIs or those accepting user-controlled header names without normalization. Rated 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), this flaw can lead to Denial of Service or, more severely, HTTP Request Smuggling. Request smuggling could enable ACL bypass, cache poisoning, or credential hijacking by exploiting inconsistent header interpretation between intermediaries and backend servers. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.24.0CPE matchmatch criteria | cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | ||
>= 7.0.0, < 7.24.0CPE matchmatch criteria | cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.