CyberRota Analysis
AI-GeneratedUndici versions prior to 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0 are vulnerable due to improper validation of the type property in blob-like request bodies, which can allow attackers to inject CRLF sequences and append arbitrary HTTP headers. This vulnerability could lead to HTTP request smuggling, enabling malicious actors to bypass security controls. Developers and organizations using affected versions of undici should prioritize upgrading to the patched versions to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)