Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9f24-jqhm-jfcw

Опубликовано: 16 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

fetch(url) leads to a memory leak in undici

Impact

Calling fetch(url) and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak.

Patches

Patched in v6.6.1

Workarounds

Make sure to always consume the incoming body.

Пакеты

Наименование

undici

npm
Затронутые версииВерсия исправления

>= 6.0.0, <= 6.6.0

6.6.1

EPSS

Процентиль: 54%
0.00315
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-401

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
redhat
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
nvd
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
debian
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In aff ...

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость функции fetch() клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 54%
0.00315
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-401