Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-61895.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-61895
Upstream
Published
2025-05-15T18:15:38Z
Modified
2026-04-21T04:31:52.787716Z
Summary
CVE-2025-47279 affecting package nodejs18 for versions less than 18.20.3-6
Details

Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.

References

Affected packages

Azure Linux:2 / nodejs18

Package

Name
nodejs18
Purl
pkg:rpm/azure-linux/nodejs18

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.20.3-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-61895.json"