Known vulnerabilities in undici - page 2

Vendor: Node.js
Software: undici
Software CPE: cpe:2.3:a:nodejs:undici:*:*:*:*:*:nodejs:*:*
Total vulnerabilities: 44
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting undici undici is affected by 44 known vulnerabilities: 33 medium, 11 low Critical High Medium Low

Vulnerabilities (44)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134754 - Improper Certificate Validation
CVE-2026-9697
CWE-295 Medium
No
No
7.28.0, 8.5.0 17.06.2026 SB2026061760
SB20260720393
SB2026082715
and 3 more
#VU134753 - Allocation of Resources Without Limits or Throttling
CVE-2026-12151
CWE-770 Medium
No
No
6.26.0, 7.28.0, 8.5.0 17.06.2026 SB2026061760
SB20260720393
SB2026080430
and 10 more
#VU134751 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-6733
CWE-367 Low
No
No
6.26.0, 7.28.0, 8.5.0 17.06.2026 SB2026061760
SB2026080430
SB2026082715
and 6 more
#VU127582 - Allocation of Resources Without Limits or Throttling
CVE-2026-22036
CWE-770 Medium
No
No
6.23.0, 7.18.2 24.04.2026 SB20260424138
SB20260424156
SB20260424157
and 6 more
#VU127581 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-1525
CWE-444 Medium
No
No
6.24.0, 7.24.0 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 12 more
#VU127580 - Allocation of Resources Without Limits or Throttling
CVE-2026-2581
CWE-770 Medium
No
No
7.24.0 24.04.2026 SB20260424137
SB20260424153
SB20260424154
and 3 more
#VU127579 - Improper Validation of Specified Quantity in Input
CVE-2026-1528
CWE-1284 Medium
No
No
6.24.0, 7.24.0 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 13 more
#VU127578 - Improper Validation of Specified Quantity in Input
CVE-2026-2229
CWE-1284 Medium
No
No
6.24.0, 7.24.0 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 12 more
#VU127577 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-1527
CWE-93 Low
No
No
6.24.0, 7.24.0 24.04.2026 SB20260424137
SB20260424148
SB20260424153
and 10 more
#VU127576 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-1526
CWE-409 Medium
No
No
6.24.0, 7.24.0 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 12 more
#VU109244 - Missing release of memory after effective lifetime
CVE-2025-47279
CWE-401 Medium
No
No
5.29.0, 6.21.2, 7.5.0 16.05.2025 SB2025051606
SB2025052019
SB2025090104
and 5 more
#VU103227 - Use of Insufficiently Random Values
CVE-2025-22150
CWE-330 Medium
No
No
5.28.5, 6.21.1, 7.2.3 22.01.2025 SB2025012259
SB2025012439
SB2025012440
and 27 more
#VU93884 - Missing release of memory after effective lifetime
CVE-2024-38372
CWE-401 Medium
No
No
6.19.2 09.07.2024 SB2024070938
SB2024082714
SB2025032026
and 1 more
#VU88178 - Insufficient Verification of Data Authenticity
CVE-2024-30261
CWE-345 Medium
No
No
5.28.4, 6.11.1 05.04.2024 SB2024040527
SB2024041611
SB2024041618
and 12 more
#VU88177 - Exposure of sensitive information to an unauthorized actor
CVE-2024-30260
CWE-200 Low
No
No
5.28.4, 6.11.1 05.04.2024 SB2024040527
SB2024041611
SB2024041618
and 11 more
#VU86710 - Resource exhaustion
CVE-2024-24750
CWE-400 Medium
No
No
6.6.1 22.02.2024 SB2024022211
SB2024052127
#VU86709 - Exposure of sensitive information to an unauthorized actor
CVE-2024-24758
CWE-200 Low
No
No
5.28.3, 6.6.1 22.02.2024 SB2024022211
SB2024022225
SB2024022832
and 13 more
#VU82066 - Exposure of sensitive information to an unauthorized actor
CVE-2023-45143
CWE-200 Medium
No
No
5.26.2 17.10.2023 SB2023101702
SB2023101703
SB2023101801
and 31 more
#VU72404 - Incorrect Regular Expression
CVE-2023-24807
CWE-185 Medium
No
No
5.19.1 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 34 more
#VU72403 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-23936
CWE-113 Medium
No
No
5.19.1 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 35 more


Showing elements 21 - 40 out of 44