nodejs undici
19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
integrity option passed to fetch(),fetch(url) and not consuming the inHeaders.set() and Headers.append() methods are vulnerab=< undici@5.8.0 users are vulnerable to _CRLF Injection_ on headeundici is vulnerable to SSRF (Server-side Request Forgery) when aUndici.ProxyAgent never verifies the remote server's certificate, and always exposes all request & response data to the proxy. T