Input validation error in undici - CVE-2026-84947

 

Input validation error in undici - CVE-2026-84947

Published: September 6, 2026


Vulnerability identifier: #VU147177
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-84947
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause response truncation.

The vulnerability exists due to improper input validation in the dump interceptor when processing oversized chunked responses without a Content-Length header. A remote attacker can send an oversized chunked response to cause response truncation.

Exploitation requires the application to use the dump interceptor with an untrusted or misbehaving upstream.


Affected software

undici

How to mitigate CVE-2026-84947

Install security update from vendor's website.

undici - addressed in versions 7.29.1, 8.10.2

External References

Related Security Bulletins