SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15157

MEDIUM · CVSS 4.2 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

Undici versions prior to 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0 are vulnerable due to improper validation of the type property in blob-like request bodies, which can allow attackers to inject CRLF sequences and append arbitrary HTTP headers. This vulnerability could lead to HTTP request smuggling, enabling malicious actors to bypass security controls. Developers and organizations using affected versions of undici should prioritize upgrading to the patched versions to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15157
Severity
MEDIUM
CVSS
4.2
EPSS
0.19%

Original NVD Description

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)