← Back

CVE-2026-6733

nvd nist
Published: Jun 17, 2026Modified: Jun 27, 2026

JSON object

Loading...
3.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.2 / Impact: 1.4
Source: ce714d77-add3-4f53-aff5-83d477b104bb (Secondary)

Description

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

Affected (3)

Products: Nodejs: Undici
1 product
Undici
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
Before 6.27.0
From 7.0.0 to 7.28.0
From 8.0.0 to 8.5.0

References (3)

Source: ce714d77-add3-4f53-aff5-83d477b104bb
Vendor Advisory
Source: ce714d77-add3-4f53-aff5-83d477b104bb
MitigationVendor Advisory
Source: ce714d77-add3-4f53-aff5-83d477b104bb
Issue Tracking

Timeline

No history available yet.