Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-05692

Опубликовано: 15 мая 2025
Источник: fstec
CVSS3: 3.1
CVSS2: 2.1
EPSS Низкий

Описание

УязвимостьHTTP клиента Undici программной платформы NodeJS связана с отсутствием освобождения памяти после эффективного срока службы. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, вызвать отказ в обслуживании

Вендор

ООО «Ред Софт»
Jenkins
Node.js Foundation

Наименование ПО

РЕД ОС
NodeJS
Undici

Версия ПО

8.0 (РЕД ОС)
до 22.19.0 (NodeJS)
до 5.29.0 (Undici)
до 6.21.2 (Undici)
до 7.5.0 (Undici)

Тип ПО

Операционная система
Прикладное ПО информационных систем
Сетевое средство

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 2,1)
Низкий уровень опасности (базовая оценка CVSS 3.1 составляет 3,1)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/nodejs/undici
https://github.com/nodejs/undici/commit/f317618ec28753a4218beccea048bcf89c36db25
https://github.com/nodejs/undici/issues/3895
https://github.com/nodejs/undici/pull/4088
https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2025-47279

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 20%
0.00281
Низкий

3.1 Low

CVSS3

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 3.1
redos
5 месяцев назад

Уязвимость nodejs20

CVSS3: 3.1
redos
5 месяцев назад

Уязвимость nodejs

CVSS3: 3.1
ubuntu
около 1 года назад

Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.

CVSS3: 3.1
redhat
около 1 года назад

Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.

CVSS3: 3.1
nvd
около 1 года назад

Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.

EPSS

Процентиль: 20%
0.00281
Низкий

3.1 Low

CVSS3

2.1 Low

CVSS2