vulnerability
Debian: CVE-2022-32210: node-undici -- security update
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:M/Au:N/C:C/I:P/A:N) | Jul 14, 2022 | Jul 30, 2024 | Mar 30, 2026 |
Severity
8
CVSS
(AV:N/AC:M/Au:N/C:C/I:P/A:N)
Published
Jul 14, 2022
Added
Jul 30, 2024
Modified
Mar 30, 2026
Description
`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.
Solution
debian-upgrade-node-undici
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.