{"id":"CVE-2026-6734","title":"undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)","summary":"A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":["CWE-940","CWE-346"],"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4.20","affected":["openshift_pipelines","build_of_podman_desktop","openshift_ai_rhoai","self_service_automation_portal 2","cryostat_4_on_rhel 9","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_v_9","cluster_observability_operator 1.5.0","developer_hub 1.10","developer_hub 1.9","hardened_images","openshift_ai 2.25","openshift_ai 3.4","openshift_dev_spaces 3.29","openshift_data_foundation 4.18","openshift_data_foundation 4.19","openshift_data_foundation 4.20"],"patched":["cryostat_4_on_rhel 9","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_8","enterprise_linux_appstream_v_9","cluster_observability_operator 1.5.0","developer_hub 1.10","developer_hub 1.9","hardened_images","openshift_ai 2.25","openshift_ai 3.4","openshift_dev_spaces 3.29","openshift_data_foundation 4.18","openshift_data_foundation 4.19","openshift_data_foundation 4.20"],"published":"2026-06-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T13:21:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6734.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6734.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-6734"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490024"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-6734"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6734"},{"url":"https://cna.openjsf.org/security-advisories.html"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj"},{"url":"https://access.redhat.com/errata/RHSA-2026:48151"},{"url":"https://access.redhat.com/errata/RHSA-2026:35841"},{"url":"https://access.redhat.com/errata/RHSA-2026:39868"},{"url":"https://access.redhat.com/errata/RHSA-2026:35891"},{"url":"https://access.redhat.com/errata/RHSA-2026:34342"},{"url":"https://access.redhat.com/errata/RHSA-2026:36754"},{"url":"https://access.redhat.com/errata/RHSA-2026:41929"},{"url":"https://access.redhat.com/errata/RHSA-2026:38236"},{"url":"https://access.redhat.com/errata/RHSA-2026:7378"},{"url":"https://access.redhat.com/errata/RHSA-2026:22380"},{"url":"https://access.redhat.com/errata/RHSA-2026:22934"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:48124"},{"url":"https://access.redhat.com/errata/RHSA-2026:36820"},{"url":"https://access.redhat.com/errata/RHSA-2026:56431"},{"url":"https://access.redhat.com/errata/RHSA-2026:56366"},{"url":"https://access.redhat.com/errata/RHSA-2026:57013"},{"url":"https://github.com/nodejs/undici/pull/5041"},{"url":"https://github.com/advisories/GHSA-hm92-r4w5-c3mj"}],"tags":["csaf","vex","red-hat","cve.org","nvd","ghsa","npm"],"epss":0.00345,"epssPercentile":0.28025,"ecosystem":"npm","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-06-22T00:00:00+00:00"},"ingestedAt":"2026-06-22T15:59:08.197Z","slug":"CVE-2026-6734","body":"## Overview\n\nA flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one destination are sent to another. Consequently, responses from unintended origins may be trusted, and secure HTTPS connections could be silently downgraded to unencrypted HTTP, resulting in information disclosure and data integrity issues.\n\n## Vendor advisories\n\n- **RHSA-2026:48151** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-07-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:48151)\n- **RHSA-2026:35841** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35841)\n- **RHSA-2026:39868** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-07-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:39868)\n- **RHSA-2026:35891** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35891)\n- **RHSA-2026:34342** · Red Hat · fixed in: Cluster Observability Operator 1.5.0 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34342)\n- **RHSA-2026:36754** · Red Hat · fixed in: Red Hat Developer Hub 1.10 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36754)\n- **RHSA-2026:41929** · Red Hat · fixed in: Red Hat Developer Hub 1.9 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:41929)\n- **RHSA-2026:38236** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:38236)\n- **RHSA-2026:7378** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-04-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:7378)\n- **RHSA-2026:22380** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22380)\n- **RHSA-2026:22934** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:22934)\n- **Red Hat VEX** · Important · affected: OpenShift Pipelines, Red Hat Build of Podman Desktop, Red Hat OpenShift AI (RHOAI), Self-service automation portal 2 · no fix planned: OpenShift Pipelines, Red Hat Build of Podman Desktop, Red Hat OpenShift AI (RHOAI), Self-service automation portal 2 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6734.json)\n\n**undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing** — rated Important by Red Hat. Released 2026-06-17, updated 2026-09-18.\n\nAffected:\n\n- OpenShift Pipelines\n- Red Hat Build of Podman Desktop\n- Red Hat OpenShift AI (RHOAI)\n- Self-service automation portal 2\n\nFixed:\n\n- Cryostat 4 on RHEL 9\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream (v. 9)\n- Cluster Observability Operator 1.5.0\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat Hardened Images\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n- Red Hat OpenShift Dev Spaces 3.29\n- Red Hat Openshift Data Foundation 4.18\n- Red Hat Openshift Data Foundation 4.19\n- Red Hat Openshift Data Foundation 4.20\n\nNo fix planned:\n\n- OpenShift Pipelines\n- Red Hat Build of Podman Desktop\n- Red Hat OpenShift AI (RHOAI)\n- Self-service automation portal 2\n\nNot affected:\n\n- Cryostat 4 on RHEL 9\n- Cluster Observability Operator 1.5.0\n- Red Hat Developer Hub 1.10\n- Red Hat Developer Hub 1.9\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n- Red Hat OpenShift Dev Spaces 3.29\n- Red Hat Openshift Data Foundation 4.18\n- Red Hat Openshift Data Foundation 4.19\n- Red Hat Openshift Data Foundation 4.20\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:48151\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:35841\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:39868\n\nWorkarounds / mitigations:\n\n- The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they…\n\n## Package advisory (CVE-2026-6734)\n\nAffected packages:\n\n- `undici >= 7.23.0, < 7.28.0`\n- `undici >= 8.0.0, < 8.2.0`\n\nPatched in:\n\n- `undici 7.28.0`\n- `undici 8.2.0`\n\nSource: https://github.com/advisories/GHSA-hm92-r4w5-c3mj","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}