Four undici Vulnerabilities Affect a Package With 133M Weekly Downloads
ID: f35c937a-b20e-5c21-a02e-24e9828d619f
STIX ID: report--f35c937a-b20e-5c21-a02e-24e9828d619f
Feed Name: securityonline.info
TL;DR: The undici HTTP client (widely used in Node.js) has four disclosed vulnerabilities—two SOCKS5 proxy issues that can route requests to the wrong origin or bypass TLS validation (enabling MITM and data leakage) and two WebSocket fragment-handling bugs that allow denial-of-service. No in-the-wild exploitation has been confirmed; patches are available (v6.27.0 / v7.28.0 / v8.2.0 / v8.5.0 depending on branch) and users should update or isolate SOCKS5 agents per origin as a stopgap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
