Vulnerabilidades em undici
30 resultadosAnálise Vexday
O undici registra 14 vulnerabilidades na base Vexday, com 8 divulgações nos últimos 90 dias indicando atividade recente de descobertas; nenhuma está sob exploração ativa (KEV) e não há críticas CVSS, reduzindo a urgência operacional imediata. A fraqueza dominante é CWE-770 (alocação de recursos sem limite apropriado), um padrão típico de negação de serviço que requer monitoramento em ambientes de alto volume.
CVE-2026-1526HIGHundici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-deflate DecompressionEPSS 1.1%CVE-2026-2229HIGHundici is vulnerable to Unhandled Exception in undici WebSocket Client Due to Invalid server_max_window_bits ValidationEPSS 0.9%CVE-2026-12151HIGHundici WebSocket client vulnerable to denial of service via fragment count bypassEPSS 0.8%CVE-2026-2581MEDIUMundici is vulnerable to Unbounded Memory Consumption in in Undici's DeduplicationHandler via Response Buffering leads to DoSEPSS 0.7%CVE-2026-13697HIGHundici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesEPSS 0.6%CVE-2026-9697HIGHundici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgentEPSS 0.6%CVE-2026-85014MEDIUMundici vulnerable to Denial of Service via WebSocketStream unclean closeEPSS 0.5%CVE-2026-1525MEDIUMundici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')EPSS 0.5%CVE-2026-1528HIGHundici is vulnerable to Malicious WebSocket 64-bit length overflows undici parser and crashes the clientEPSS 0.5%CVE-2026-9675HIGHundici WebSocket client vulnerable to denial of service via cumulative fragment bypassEPSS 0.5%CVE-2026-9678MEDIUMundici vulnerable to cross-user information disclosure via shared cache whitespace bypassEPSS 0.4%CVE-2026-85024MEDIUMundici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompressionEPSS 0.4%CVE-2026-84890MEDIUMundici vulnerable to Denial of Service via unbounded decompression of compressed responsesEPSS 0.4%CVE-2026-14643MEDIUMundici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directivesEPSS 0.4%CVE-2026-19534HIGHundici vulnerable to Denial of Service via unrequested WebSocket subprotocolEPSS 0.4%CVE-2026-6734HIGHundici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuseEPSS 0.4%CVE-2026-18149MEDIUMundici vulnerable to Denial of Service via orphaned RetryHandler response bodyEPSS 0.4%CVE-2026-84933MEDIUMundici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared cachesEPSS 0.3%CVE-2026-9679MEDIUMundici vulnerable to HTTP header injection via Set-Cookie percent-decodingEPSS 0.3%CVE-2026-84947LOWundici vulnerable to response truncation via oversized chunked responses in the dump interceptorEPSS 0.3%