Origin validation error in undici - CVE-2026-6734
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information, modify request routing, and cause requests to be sent to the wrong origin.
The vulnerability exists due to origin validation error in Socks5ProxyAgent connection pool reuse when handling requests to multiple origins through a shared proxy agent. A remote user can trigger requests to a different origin through the reused pool to disclose sensitive information, modify request routing, and cause requests to be sent to the wrong origin.
Responses from the wrong origin may be trusted, and HTTPS requests may be silently downgraded to HTTP.
Affected software
Netezza Appliance
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
nodejs22
nodejs24
How to mitigate CVE-2026-6734
Netezza Appliance - update to 1.0.2.0
nodejs22 - update to 22.23.1-2.fc44
nodejs24 - update to 24.18.0-1.fc44