Time-of-check Time-of-use (TOCTOU) Race Condition in undici - CVE-2026-6733
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause responses to be delivered to the wrong requests.
The vulnerability exists due to a time-of-check time-of-use race condition in the HTTP/1.1 client when reusing keep-alive sockets. A remote attacker can inject an unsolicited HTTP/1.1 response onto an idle socket to cause responses to be delivered to the wrong requests.
Exploitation requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.
Affected software
Netezza Appliance
Maximo Application Suite - Visual Inspection Component
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Fedora
nodejs22
nodejs24
How to mitigate CVE-2026-6733
Netezza Appliance - update to 1.0.2.0
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.22, 9.1.19, 9.2.1
nodejs22 - update to 22.23.1-2.fc44
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM Netezza Appliance
- Fedora 44 update for nodejs24
- Fedora 44 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 8 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module