undici
NPM Package
Vulnerability Check
An HTTP/1.1 client, written from scratch for Node.js
undici
Advisory Breakdown
Severity Rating
High severity30 advisories
High severity
Weekly downloads
133,047,713
Total advisories
30
Latest version
8.5.0
License
MIT
Known advisories
OSV records for the npm ecosystem
Undici has an HTTP Request/Response Smuggling issue
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
undici before v5.8.0 vulnerable to CRLF injection in request headers
Undici vulnerable to data leak when using response.arrayBuffer()
Undici has CRLF Injection in undici via `upgrade` option
CRLF Injection in Nodejs ‘undici’ via host
`undici.request` vulnerable to SSRF using absolute URL on `pathname`
fetch(url) leads to a memory leak in undici
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Use of Insufficiently Random Values in undici
undici Denial of Service attack via bad certificate data
Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
ProxyAgent vulnerable to MITM
Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
Regular Expression Denial of Service in Headers
Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression
undici WebSocket client vulnerable to denial of service via fragment count bypass
Undici's cookie header not cleared on cross-origin redirect in fetch
Checked Jun 28, 2026, 7:16 AM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- undici
- Ecosystem
- npm
- Latest version
- 8.5.0
- License
- MIT
- Weekly downloads
- 133,047,713
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/28/2026, 7:16:59 AM