Undici
Vendor:
First CVE: Jul 14, 2022 · Active for 4 years
27
Total CVEs
More Total CVEs than 96% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Undici over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2022
4 years ago
Most Recent CVE
Jun 17, 2026
37 days ago
CVE Severity & Scoring
Undici27 CVEs
15%
44%
33%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (74.1%)
High7 (25.9%)
Unknown0 (0.0%)
User Interaction
None20 (74.1%)
Unknown0 (0.0%)
Required7 (25.9%)
Privileges Required
Low4 (14.8%)
High2 (7.4%)
None21 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6734HIGH Impact:
When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requ | Jun 17, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-12151HIGH Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malici | Jun 17, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-9697HIGH Impact:
undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tun | Jun 17, 2026 | 7.4 | 35 | NO | NO |
CVE-2026-9675HIGH Impact:
The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can | Jun 17, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-1525CRITICAL Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HT | Mar 12, 2026 | 9.8 | 33 | NO | NO |
CVE-2022-35949CRITICAL undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `pa | Aug 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-9679MEDIUM Impact:
undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equi | Jun 17, 2026 | 5.9 | 30 | NO | NO |
CVE-2026-9678MEDIUM Impact:
Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache fi | Jun 17, 2026 | 5.9 | 29 | NO | NO |
CVE-2026-1528HIGH ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state | Mar 12, 2026 | 7.5 | 29 | NO | NO |
CVE-2026-1526HIGH The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negoti | Mar 12, 2026 | 7.5 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Undici
Top CWEs
Versions
No cataloged versions.