Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-pmjh-fq2x-6v4x
  • npm/undici
undici vulnerable to Denial of Service via orphaned RetryHandler response body 6 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-r53p-7pc4-xj5r
  • npm/undici
undici vulnerable to downstream response splitting via retry interceptor 6 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-rfgv-xxqx-mfg5
  • npm/undici
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol 6 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-3xpg-4rpp-hhhm
  • npm/undici
undici vulnerable to Denial of Service via unbounded decompression of compressed responses 6 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-2jfj-6hjv-fm6j
  • npm/undici
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches 6 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2gqq-gqf2-x968
  • npm/undici
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor 6 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-w293-vg96-wgc3
  • npm/undici
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool 6 days ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-8436-99hf-9mmv
  • npm/undici
undici vulnerable to caching and replay of unsafe HTTP method responses 6 days ago
  • Fix available
  • Severity - 3.7 (Low)
GHSA-vp8m-p9jh-q5pm
  • npm/undici
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors 6 days ago
  • Fix available
  • Severity - 7.4 (High)
GHSA-rx4f-c7p8-82vq
  • npm/undici
undici vulnerable to Denial of Service via WebSocketStream unclean close 6 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-3wwx-pv8p-q78v
  • npm/undici
undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression 28 Sep
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-m8rv-5g2x-5cg5
  • npm/undici
undici vulnerable to CRLF Injection via blob-like body 'type' property 03 Aug
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-jr45-8vmc-qm54
  • npm/undici
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives 03 Aug
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-v3r7-h72x-cjcm
  • npm/undici
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields 03 Aug
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8xcm-r25x-g524
  • npm/undici
undici vulnerable to downstream response desynchronization via retry interceptor 03 Aug
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-4cwx-7wf7-3272
  • npm/undici
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives 03 Aug
  • Fix available
  • Severity - 7.4 (High)