CVE Tools

Undici

19 CVEs tracked since 2026. Since Jun 2026, none of them reached CISA KEV.

Undici CVEs per month

Jun 2026 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Undici CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0680
2026-07null or fewer
2026-08null or fewer
2026-09110

Products

The products that kept showing up in Undici's monthly top three, with their CVEs summed over those months.

  1. Undici192 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Undici.

  1. CVE-2026-18149undici vulnerable to Denial of Service via orphaned RetryHandler response body5.9
  2. CVE-2026-18540undici vulnerable to downstream response splitting via retry interceptor3.7
  3. CVE-2026-19534undici vulnerable to Denial of Service via unrequested WebSocket subprotocol7.5
  4. CVE-2026-84890undici vulnerable to Denial of Service via unbounded decompression of compressed responses5.9
  5. CVE-2026-84933undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches6.5
  6. CVE-2026-84947undici vulnerable to response truncation via oversized chunked responses in the dump interceptor3.7
  7. CVE-2026-84961undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool7.4
  8. CVE-2026-85008undici vulnerable to caching and replay of unsafe HTTP method responses3.7
  9. CVE-2026-85152undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors7.4
  10. CVE-2026-85014undici vulnerable to Denial of Service via WebSocketStream unclean close5.9
  11. CVE-2026-85024undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression5.9
  12. CVE-2026-15157undici vulnerable to CRLF Injection via blob-like body 'type' property4.2
  13. CVE-2026-14643undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives5.9
  14. CVE-2026-16728undici vulnerable to downstream response desynchronization via retry interceptor4.8
  15. CVE-2026-16729undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields4.8

The record

Peak rank
#116 in Sep 2026
Busiest month shown
Sep 2026, 11 CVEs
Months with a KEV entry
0 since Jun 2026
Monthly snapshots
2 since 2026
Undici's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store