CVE-2026-6733

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*

History

27 Jun 2026, 23:46

Type Values Removed Values Added
CPE cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
First Time Nodejs
Nodejs undici
References () https://cna.openjsf.org/security-advisories.html - () https://cna.openjsf.org/security-advisories.html - Vendor Advisory
References () https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 - () https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52 - Mitigation, Vendor Advisory
References () https://hackerone.com/reports/3582376 - () https://hackerone.com/reports/3582376 - Issue Tracking

17 Jun 2026, 20:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 18:18

Updated : 2026-06-27 23:46


NVD link : CVE-2026-6733

Mitre link : CVE-2026-6733

CVE.ORG link : CVE-2026-6733


JSON object : View

Products Affected

nodejs

  • undici
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition