Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

undici vulnerable to downstream response desynchronization via retry interceptor (CVE-2026-16728)CVE-2026-16728
0

Undici versions prior to 6.28.0, 7.29.0, and 8.9.0 contain a vulnerability in the interceptors.retry() feature where the response body length may not match the Content-Length header after retrying or resuming a partial response. This mismatch can cause downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the Content-Length header for framing. The issue arises when an upstream server returns a partial content response with incorrect Content-Length, and the retry interceptor retries the request, resulting in a stale Content-Length header being forwarded. The vulnerability is patched in undici versions 6.28.0, 7.29.0, and 8.9.0 and later.

Join the discussion
Security fixes in n8n 2.28.0-r2 (CVE-2026-14643)CVE-2026-14643
0

n8n versions prior to 2.28.0-r2, including versions from 7.0.0 up to but not including 7.29.0 and 8.0.0 up to but not including 8.9.0, are affected by multiple vulnerabilities including CVE-2026-14643. This vulnerability is classified with moderate severity and relates to security weaknesses identified by CWE-436 and CWE-524. The issue has been addressed in n8n version 2.28.0-r2, which includes fixes for 46 vulnerabilities. No known exploits are reported in the wild at this time.

Join the discussion
undici vulnerable to CRLF Injection via blob-like body 'type' propertyCVE-2026-15157
0

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:npm/undici
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses