Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-22036

Опубликовано: 14 янв. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 5.9

Описание

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

РелизСтатусПримечание
devel

needs-triage

esm-apps/noble

needs-triage

jammy

DNE

noble

needs-triage

plucky

ignored

end of life, was needs-triage
questing

needs-triage

upstream

needs-triage

Показывать по

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
24 дня назад

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.

CVSS3: 5.9
debian
24 дня назад

Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, ...

CVSS3: 5.9
github
24 дня назад

Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion

suse-cvrf
11 дней назад

Security update for nodejs22

suse-cvrf
12 дней назад

Security update for nodejs22

5.9 Medium

CVSS3