Inconsistent interpretation of HTTP requests in undici - CVE-2026-1525

 

Inconsistent interpretation of HTTP requests in undici - CVE-2026-1525

Published: April 24, 2026


Vulnerability identifier: #VU127581
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-1525
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to smuggle HTTP requests.

The vulnerability exists due to inconsistent interpretation of HTTP requests in undici low-level HTTP request APIs when processing headers passed as flat arrays with case-variant duplicate Content-Length names. A remote attacker can supply specially crafted header arrays to smuggle HTTP requests.

Exploitation requires an intermediary and backend to interpret duplicate Content-Length headers inconsistently.


Affected software

undici
IBM Cloud Pak System
DataStage on Cloud Pak for Data
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs20
nodejs22 (Red Hat package)
nodejs22
nodejs24 (Red Hat package)

How to mitigate CVE-2026-1525

Install security update from vendor's website.

undici - addressed in versions 6.24.0, 7.24.0
IBM Cloud Pak System - update to 2.3.5.1
DataStage on Cloud Pak for Data - update to 5.4
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.23, 16.1.3.6
nodejs20 - update to 20.20.2-3.fc43
nodejs22 (Red Hat package) - addressed in versions 22.22.2-1.el10_1, 22.22.2-2.el10_0
nodejs22 - addressed in versions 22.22.2-2.fc43, 22.22.2-3.fc42, 22.22.2-3.fc44
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1

External References

Related Security Bulletins