Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-22036

Опубликовано: 14 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.9

Описание

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

РелизСтатусПримечание
devel

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

needs-triage

plucky

ignored

end of life, was needs-triage
questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

needs-triage

Показывать по

EPSS

Процентиль: 37%
0.0044
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
7 месяцев назад

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

CVSS3: 5.9
nvd
7 месяцев назад

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

CVSS3: 5.9
debian
7 месяцев назад

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, ...

CVSS3: 5.9
github
7 месяцев назад

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

suse-cvrf
6 месяцев назад

Security update for nodejs22

EPSS

Процентиль: 37%
0.0044
Низкий

5.9 Medium

CVSS3