Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade nodejs20-libsUpgrade nodejs20-docsUpgrade nodejs22Upgrade nodejs22-debuginfoUpgrade nodejs22-full-i18nUpgrade nodejs22-docsUpgrade nodejs20-debugsourceUpgrade v8-12.4-develUpgrade nodejs22-npmUpgrade nodejs22-debugsourceUpgrade nodejs22-develUpgrade v8-11.3-develUpgrade nodejs20-full-i18nUpgrade nodejs20-npmUpgrade nodejs20-libs-debuginfoUpgrade nodejs20Upgrade nodejs20-debuginfoUpgrade nodejs22-libsUpgrade nodejs20-develUpgrade nodejs22-libs-debuginfo | Jun 11, 2025 | May 15, 2025 |
| Debian | — | No solution exists | May 20, 2025 | May 15, 2025 |
| Red Hat Jboss Eap | — | — | May 19, 2025 | May 15, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub