CVE-2026-84961

Source
https://cve.org/CVERecord?id=CVE-2026-84961
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84961.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84961
Aliases
  • GHSA-w293-vg96-wgc3
Downstream
Published
2026-09-04T16:47:55Z
Modified
2026-09-06T03:30:27Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
Details

undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.

Database specific
{
    "cna_assigner": "openjs",
    "cwe_ids": [
        "CWE-295"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84961.json"
}
References

Affected packages

Git / github.com/nodejs/undici

Affected ranges

Type
GIT
Repo
https://github.com/nodejs/undici
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.24.1"
        },
        {
            "fixed": "7.29.1"
        },
        {
            "introduced": "8.0.0"
        },
        {
            "fixed": "8.10.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v7.*
v7.24.1
v7.24.2
v7.24.3
v7.24.4
v7.24.5
v7.24.6
v7.24.7
v7.24.8
v7.25.0
v7.26.0
v7.27.0
v7.27.1
v7.27.2
v7.28.0
v7.29.0
v8.*
v8.0.0
v8.0.1
v8.0.2
v8.0.3
v8.1.0
v8.10.0
v8.10.1
v8.2.0
v8.3.0
v8.4.0
v8.4.1
v8.5.0
v8.6.0
v8.7.0
v8.8.0
v8.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84961.json"