undici has 10 CVEs on record. Cadence is steady at roughly 5 per quarter. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 5 prev 5
Worst active — by depth score
CVE-2026-13697High· 7.4undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives41CVE-2026-9675High· 7.5undici WebSocket client vulnerable to denial of service via cumulative fragment bypass41CVE-2026-14643Medium· 5.9undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives33CVE-2026-9679Medium· 5.9undici vulnerable to HTTP header injection via Set-Cookie percent-decoding33CVE-2026-9678Medium· 5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass33
undici vulnerabilities
CVEs affecting undici, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-16729Medium· 4.8undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-14643Medium· 5.9undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVE-2026-15157Medium· 4.2undici vulnerable to CRLF Injection via blob-like body 'type' property
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-13697High· 7.4undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVE-2026-16728Medium· 4.8undici vulnerable to downstream response desynchronization via retry interceptor
undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-6733Low· 3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
CVE-2026-9679Medium· 5.9undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
CVE-2026-11525Low· 3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-9675High· 7.5undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2026-9678Medium· 5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass