Inconsistent interpretation of HTTP requests in undici - CVE-2026-1525
Published: April 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to smuggle HTTP requests.
The vulnerability exists due to inconsistent interpretation of HTTP requests in undici low-level HTTP request APIs when processing headers passed as flat arrays with case-variant duplicate Content-Length names. A remote attacker can supply specially crafted header arrays to smuggle HTTP requests.
Exploitation requires an intermediary and backend to interpret duplicate Content-Length headers inconsistently.
Affected software
IBM Cloud Pak System
DataStage on Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs20
nodejs22 (Red Hat package)
nodejs22
nodejs24 (Red Hat package)
How to mitigate CVE-2026-1525
IBM Cloud Pak System - update to 2.3.5.1
DataStage on Cloud Pak for Data - update to 5.4
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
nodejs20 - update to 20.20.2-3.fc43
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs22 - addressed in versions 22.22.2-2.fc43, 22.22.2-3.fc42, 22.22.2-3.fc44
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Fedora 43 update for nodejs20
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 10 update for nodejs24
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Fedora 44 update for nodejs22
- Fedora 43 update for nodejs22
- Multiple vulnerabilities in IBM Platform Navigator in IBM Cloud Pak for Integration (CP4I)
- Fedora 42 update for nodejs22
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak System Software