Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade nodejs24Upgrade nodejs24-debugsourceUpgrade nodejs24-full-i18nUpgrade nodejs24-libsUpgrade v8-13.6-develUpgrade nodejs24-develUpgrade nodejs24-libs-debuginfoUpgrade nodejs24-docsUpgrade nodejs24-npmUpgrade nodejs24-debuginfo | Feb 10, 2026 | Jan 14, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 14, 2026 |
| Suse | — | Upgrade npm20Upgrade corepack22Upgrade nodejs22-docsUpgrade nodejs20-develUpgrade nodejs22Upgrade corepack20Upgrade npm22Upgrade nodejs22-develUpgrade nodejs20Upgrade nodejs20-docs | Jan 27, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub