undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1
Details
CVE-2026-15157 affects multiple packages. undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1. See references for individual vulnerability details.