Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-30261

15
FAUCET Score

CVE-2024-30261 is a low-severity vulnerability affecting Undici, an HTTP/1.1 client for Node.js, specifically impacting fedoraproject and nodejs distributions. An attacker can manipulate the integrity option in fetch() requests, potentially allowing tampered data to be accepted as valid. The attack requires user interaction and has a low impact on integrity, with no confidentiality or availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.28.4CPE matchmatch criteria
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
>= 6.0.0, < 6.11.1CPE matchmatch criteria
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
40CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

2.6LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.80%
Probability of exploitation in next 30 days
EPSS Percentile
53.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0080 is in the 92nd percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 nodejs 20.10.0-2 on Azure Linux 3.0Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: 16990-17084Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: 19740-17084Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: cbl2 nodejs18 18.20.2-1 on CBL Mariner 2.0Fixed in: 18.20.2-1
microsoftpatch availablevia msrc
Product: cbl2 nodejs18 18.18.2-7 on CBL Mariner 2.0Fixed in: 18.20.2-1
microsoftpatch availablevia msrc
Product: azl3 nodejs 20.14.0-1 on Azure Linux 3.0Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 18.20.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 18.20.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 20.14.0-1
microsoftpatch availablevia msrc
Product: 17347-16823Fixed in: 18.20.2-1
microsoftpatch availablevia msrc
Product: 19748-17086Fixed in: 18.20.2-1
npmpatch availablevia ghsa
Product: undiciFixed in: 6.11.1
npmpatch availablevia ghsa
Product: undiciFixed in: 5.28.4
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/dashboard-rhel8:3.16-27
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub (RHDH) 1.4Fixed in: rhdh/rhdh-hub-rhel9:sha256:5eb109362246ccddd564febe6387bc6015d47555df00c36aa88c2247099851b7
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.keycloak-keycloak-parent

Vendor Advisories (4)

microsoft2024-Dec/CVE-2024-30261

CVE-2024-30261

Dec 10, 2024
microsoft2024-Apr/CVE-2024-30261Low

Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect

Apr 9, 2024
npmGHSA-9qxr-qj54-h672low

Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect

Apr 4, 2024
redhatCVE-2024-30261Low

nodejs-undici: fetch() with integrity option is too lax when algorithm is specified but hash value is in incorrect

Apr 4, 2024

References

security.netapp.com / advisory/ntap-20240905-0008
github.com / nodejs/undici/commit/2b39440bd9ded841c93dd72138f3b1763ae26055
Patch
github.com / nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3
Patch
github.com / nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672
Vendor Advisory
hackerone.com / reports/2377760
ExploitIssue Tracking
lists.fedoraproject.org / archives/list/[email protected]/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33
Product
lists.fedoraproject.org / archives/list/[email protected]/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ
Product
lists.fedoraproject.org / archives/list/[email protected]/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E
Product