CRLF injection in undici - CVE-2026-1527
Published: April 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary HTTP headers and smuggle raw data to non-HTTP services.
The vulnerability exists due to improper neutralization of CRLF sequences in the upgrade option of client.request() when processing user-controlled input. A remote attacker can supply a specially crafted upgrade value to inject arbitrary HTTP headers and smuggle raw data to non-HTTP services.
User interaction is required because an application must pass user-controlled input to the upgrade option.
Affected software
IBM Cloud Pak System
DataStage on Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Fedora
nodejs20
nodejs22
nodejs24 (Red Hat package)
How to mitigate CVE-2026-1527
IBM Cloud Pak System - update to 2.3.5.1
DataStage on Cloud Pak for Data - update to 5.4
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
nodejs20 - update to 20.20.2-3.fc43
nodejs22 - addressed in versions 22.22.2-2.fc43, 22.22.2-3.fc42, 22.22.2-3.fc44
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Fedora 43 update for nodejs20
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 10 update for nodejs24
- Fedora 44 update for nodejs22
- Fedora 43 update for nodejs22
- Multiple vulnerabilities in IBM Platform Navigator in IBM Cloud Pak for Integration (CP4I)
- Fedora 42 update for nodejs22
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System Software