Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/undici

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

The undici HTTP client library is vulnerable to a denial of service (DoS) attack via unbounded decompression of compressed HTTP response bodies. The decompress interceptor decompresses responses based on the Content-Encoding header without limiting the total decompressed size, allowing a small compressed payload to expand massively in memory and crash or hang the Node.js process. This affects applications using the decompress interceptor with untrusted upstreams. Fixed in versions 7.29.1 and 8.10.2 by adding a maxSize limit on decompressed output.

Join the discussion

undici versions 7.0.0 through before 7.29.1 and 8.0.0 through before 8.10.2 have a vulnerability in the shared cache interceptor where Set-Cookie headers are cached and re-served to other users. This can lead to cross-user cookie disclosure and allows untrusted upstreams to inject cookies into cached responses, violating RFC 6265. Private cache mode is not affected. The issue is fixed in versions 7.29.1 and 8.10.2.

Join the discussion

The undici HTTP client library's dump interceptor has a vulnerability where oversized chunked responses can cause response truncation. When the response body exceeds a configured maxSize without a declared Content-Length, the interceptor ends the response early, causing the application to see a misleading 200 status with a truncated or empty body. This affects applications using the dump interceptor with untrusted or misbehaving upstream servers. Fixed in versions 7.29.1 and 8.10.2.

Join the discussion

undici's BalancedPool component improperly handles TLS options by deep cloning constructor options via JSON, which drops function-valued connect or tls options such as custom checkServerIdentity callbacks. This causes TLS certificate validation bypass when using BalancedPool with such custom callbacks, allowing acceptance of TLS peers that should be rejected. Other undici components like Client, Pool, and Agent are not affected. The issue is fixed in versions 7.29.1 and 8.10.2.

Join the discussion

undici's cache interceptor improperly caches responses to unsafe HTTP methods like POST, PUT, PATCH, and DELETE due to a logic flaw in its skip-list and cache storage checks. This can cause state-changing requests to be bypassed, with cached responses served instead, potentially leading to inconsistent application state. The issue affects versions from 7.0.0 up to but not including 7.29.1 and from 8.0.0 up to but not including 8.10.2. A fix is available in versions 7.29.1 and 8.10.2 that prevents caching of unsafe method responses while still invalidating cache entries on successful unsafe requests. No workarounds are provided.

Join the discussion

A vulnerability in the undici HTTP client library (versions 8.10.0 and 8.10.1) allows cross-origin cache poisoning due to missing origin isolation in cache and deduplication interceptors. This flaw causes cache keys to omit the destination origin, enabling an attacker controlling one origin's response to poison the cache for another trusted origin. This can lead to information disclosure and authentication bypass scenarios, such as accepting attacker-signed tokens as valid. The issue does not affect the default Agent-based dispatch path. A patch is available in undici version 8.10.2.

Join the discussion

A denial of service vulnerability exists in undici's WebSocketStream API where an abrupt WebSocket connection closure without a proper close handshake causes the client process to crash. This occurs because the internal socket-close handler aborts a writable stream while a writer lock is held, leading to an unhandled promise rejection that terminates the Node.js process. All undici versions from 7.0.0 up to but not including 7.29.1, and from 8.0.0 up to but not including 8.10.2 are affected. The issue can be triggered by a malicious or compromised WebSocket server. Patches are available in versions 7.29.1 and 8.10.2. No workaround is currently available.

Join the discussion

A vulnerability in undici's WebSocket client causes the Node.js process to crash when receiving a specially crafted permessage-deflate compressed message that exceeds the decompressed payload size limit and contains a malformed DEFLATE block. This occurs because an internal zlib InflateRaw stream emits an unhandled error, leading to process termination. The issue affects undici versions 6.25.0 through before 6.28.1, 7.28.0 through before 7.29.1, and 8.1.0 through before 8.10.2. No workaround is available, but patched versions have been released.

Join the discussion

Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, including updates to nodejs24 and nodejs26 packages. The advisory addresses multiple CVEs (CVE-2026-18540, CVE-2026-19534, CVE-2026-84961, CVE-2026-85024) with bug fixes and enhancements. Updated RPMs cover various architectures including aarch64 and x86_64. No known exploits are reported in the wild. The advisory provides updated package versions to mitigate the vulnerabilities.

Join the discussion
0

n8n versions prior to 2.28.0-r2, including versions from 7.0.0 up to but not including 7.29.0 and 8.0.0 up to but not including 8.9.0, are affected by multiple vulnerabilities including CVE-2026-14643. This vulnerability is classified with moderate severity and relates to security weaknesses identified by CWE-436 and CWE-524. The issue has been addressed in n8n version 2.28.0-r2, which includes fixes for 46 vulnerabilities. No known exploits are reported in the wild at this time.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Package: pkg:npm/undici
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses