Описание
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling fetch(url) and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.
An uncontrolled resource consumption flaw was found in undici. Calling fetch(url) and not consuming the incoming body or consuming it very slowly leads to a memory leak.
Отчет
Users unable to upgrade should make sure to always consume the incoming body.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | undici | Not affected | ||
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | ||
| Red Hat Enterprise Linux 10 | nodejs-undici | Not affected | ||
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel9 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel8 | Not affected |
Показывать по
Дополнительная информация
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.
Undici is an HTTP/1.1 client, written from scratch for Node.js. In aff ...
Уязвимость функции fetch() клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3