undici
NPM Package
Vulnerability Check
An HTTP/1.1 client, written from scratch for Node.js
undici
Advisory Breakdown
Severity Rating
High severity22 advisories
High severity
Weekly downloads
127,518,613
Total advisories
22
Latest version
8.4.1
License
MIT
Known advisories
OSV records for the npm ecosystem
Undici has an HTTP Request/Response Smuggling issue
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
undici before v5.8.0 vulnerable to CRLF injection in request headers
Undici vulnerable to data leak when using response.arrayBuffer()
Undici has CRLF Injection in undici via `upgrade` option
CRLF Injection in Nodejs ‘undici’ via host
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
fetch(url) leads to a memory leak in undici
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Use of Insufficiently Random Values in undici
undici Denial of Service attack via bad certificate data
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
ProxyAgent vulnerable to MITM
Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
Regular Expression Denial of Service in Headers
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
Undici's cookie header not cleared on cross-origin redirect in fetch
Checked Jun 14, 2026, 10:43 PM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- undici
- Ecosystem
- npm
- Latest version
- 8.4.1
- License
- MIT
- Weekly downloads
- 127,518,613
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/14/2026, 10:43:58 PM