Known Vulnerabilities for Undici by Nodejs
Listed below are 10 of the newest known vulnerabilities associated with "Undici" by "Nodejs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-16729 json | undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-16728 json | undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the a... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-16221 json | Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not t... | Not Provided | 2026-07-19 | 2026-07-20 |
| CVE-2026-15157 json | undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header ... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-14643 json | undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Ca... | Not Provided | 2026-07-29 | 2026-07-30 |
| CVE-2026-13697 json | undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-12151 json | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does n... | Not Provided | 2026-06-17 | 2026-07-30 |
| CVE-2026-11525 json | Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-9697 json | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks:... | Not Provided | 2026-06-17 | 2026-07-30 |
| CVE-2026-9679 json | Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like... | Not Provided | 2026-06-17 | 2026-06-23 |