Known Vulnerabilities for Undici by Nodejs
Listed below are 8 of the newest known vulnerabilities associated with "Undici" by "Nodejs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-45143 json | Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization ... | 3.5 - LOW | 2023-10-12 | 2023-11-03 |
| CVE-2023-24807 json | Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vul... | 7.5 - HIGH | 2023-02-16 | 2023-02-24 |
| CVE-2023-23936 json | Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does no... | 5.4 - MEDIUM | 2023-02-16 | 2023-02-24 |
| CVE-2022-35949 json | undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) w... | 9.8 - CRITICAL | 2022-08-12 | 2023-03-28 |
| CVE-2022-35948 json | undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on ... | 5.3 - MEDIUM | 2022-08-15 | 2023-03-28 |
| CVE-2022-32210 json | `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the pro... | 6.5 - MEDIUM | 2022-07-14 | 2022-07-25 |
| CVE-2022-31151 json | Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are offic... | 6.5 - MEDIUM | 2022-07-21 | 2022-09-29 |
| CVE-2022-31150 json | undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers ... | 6.5 - MEDIUM | 2022-07-19 | 2022-10-28 |