Improper Certificate Validation in undici - CVE-2026-9697
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to intercept and modify HTTPS traffic.
The vulnerability exists due to improper certificate validation in ProxyAgent and Socks5ProxyAgent when establishing HTTPS connections through a SOCKS5 proxy. A remote attacker can present a certificate signed by a publicly trusted CA for the target hostname to intercept and modify HTTPS traffic.
Only applications that rely on requestTls settings for TLS scope restriction when using a SOCKS5 proxy are affected.
Affected software
Netezza Appliance
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat OpenShift Container Platform
nodejs24
How to mitigate CVE-2026-9697
Netezza Appliance - update to 1.0.2.0
Red Hat OpenShift Container Platform - update to 4.16.66
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Netezza Appliance
- Fedora 44 update for nodejs24
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:24 module