Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.
Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.
Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.
Patches: Upgrade to undici v7.28.0 or v8.5.0.
Workarounds: No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade nodejs-packagingUpgrade nodejs-nodemonUpgrade nodejs-develUpgrade nodejs-docsUpgrade nodejs-libsUpgrade v8-13.6-develUpgrade nodejsUpgrade nodejs-packaging-bundlerUpgrade nodejs-full-i18nUpgrade npm | Jul 7, 2026 | Jul 6, 2026 |
| Amazon_linux_2023 | — | Upgrade nodejs24-docsUpgrade nodejs24-libs-debuginfoUpgrade nodejs24-debuginfoUpgrade nodejs24-debugsourceUpgrade nodejs24-full-i18nUpgrade nodejs24-develUpgrade v8-13.6-develUpgrade nodejs24-npmUpgrade nodejs24Upgrade nodejs24-libs | Jul 8, 2026 | Jun 17, 2026 |
| Redhat_linux | — | Upgrade nodejs-develUpgrade nodejs24-libs-debuginfoUpgrade nodejs-libsUpgrade nodejs24-develUpgrade v8-13.6-develUpgrade nodejs-full-i18nUpgrade npmUpgrade nodejs24-libsUpgrade nodejsUpgrade nodejs24Upgrade nodejs24-npmUpgrade nodejs-nodemonUpgrade nodejs-debugsourceUpgrade nodejs-packagingUpgrade nodejs-debuginfoUpgrade nodejs24-docsUpgrade nodejs-docsUpgrade nodejs24-debuginfoUpgrade nodejs24-full-i18nUpgrade nodejs24-debugsourceUpgrade nodejs-packaging-bundlerUpgrade nodejs-libs-debuginfo | Jul 7, 2026 | Jun 17, 2026 |
| Rocky_linux | — | Upgrade nodejs-debuginfoUpgrade nodejs24-debugsourceUpgrade nodejsUpgrade nodejs-full-i18nUpgrade nodejs-debugsourceUpgrade nodejs-libs-debuginfoUpgrade nodejs-libsUpgrade nodejs24Upgrade nodejs24-libsUpgrade nodejs-develUpgrade v8-13.6-develUpgrade nodejs24-develUpgrade nodejs24-libs-debuginfoUpgrade nodejs24-full-i18nUpgrade nodejs24-debuginfo | Jul 13, 2026 | Jul 7, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub