Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade nodejs22-develUpgrade v8-11.3-develUpgrade nodejs22-libs-debuginfoUpgrade nodejs20Upgrade nodejs22-npmUpgrade v8-12.4-develUpgrade nodejs22-libsUpgrade nodejs20-full-i18nUpgrade nodejs20-libs-debuginfoUpgrade nodejs20-debugsourceUpgrade nodejs20-develUpgrade nodejs20-npmUpgrade nodejs22-debugsourceUpgrade nodejs20-debuginfoUpgrade nodejs22-full-i18nUpgrade nodejs20-libsUpgrade nodejs22-docsUpgrade nodejs22-debuginfoUpgrade nodejs22Upgrade nodejs20-docs | Jun 11, 2025 | May 15, 2025 |
| Debian | — | No solution exists | May 20, 2025 | May 15, 2025 |
| Red Hat Jboss Eap | — | — | May 19, 2025 | May 15, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 15, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub