Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 24

Количество 24

github логотип

GHSA-35p6-xmwp-9g52

3 месяца назад

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2026-6733

3 месяца назад

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2026-6733

3 месяца назад

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-6733

3 месяца назад

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-6733

3 месяца назад

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poiso ...

CVSS3: 3.7
EPSS: Низкий
rocky логотип

RLSA-2026:41947

около 2 месяцев назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35892

2 месяца назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35842

2 месяца назад

Important: nodejs22 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-41947

около 2 месяцев назад

ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35892

2 месяца назад

ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35842

2 месяца назад

ELSA-2026-35842: nodejs22 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:39868

2 месяца назад

Important: nodejs:24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35891

2 месяца назад

Important: nodejs:24 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2026:35841

2 месяца назад

Important: nodejs24 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39868

около 2 месяцев назад

ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35891

2 месяца назад

ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-35841

2 месяца назад

ELSA-2026-35841: nodejs24 security, bug fix, and enhancement update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2695-1

3 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2647-1

3 месяца назад

Security update for nodejs22

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21236-1

2 месяца назад

Security update for nodejs24

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-35p6-xmwp-9g52

undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse

CVSS3: 3.7
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-6733

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

CVSS3: 3.7
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6733

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

CVSS3: 3.7
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6733

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

CVSS3: 3.7
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-6733

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poiso ...

CVSS3: 3.7
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:41947

Important: nodejs:22 security, bug fix, and enhancement update

около 2 месяцев назад
rocky логотип
RLSA-2026:35892

Important: nodejs:22 security, bug fix, and enhancement update

2 месяца назад
rocky логотип
RLSA-2026:35842

Important: nodejs22 security, bug fix, and enhancement update

2 месяца назад
oracle-oval логотип
ELSA-2026-41947

ELSA-2026-41947: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-35892

ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-35842

ELSA-2026-35842: nodejs22 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
rocky логотип
RLSA-2026:39868

Important: nodejs:24 security, bug fix, and enhancement update

2 месяца назад
rocky логотип
RLSA-2026:35891

Important: nodejs:24 security, bug fix, and enhancement update

2 месяца назад
rocky логотип
RLSA-2026:35841

Important: nodejs24 security, bug fix, and enhancement update

2 месяца назад
oracle-oval логотип
ELSA-2026-39868

ELSA-2026-39868: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-35891

ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-35841

ELSA-2026-35841: nodejs24 security, bug fix, and enhancement update (IMPORTANT)

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2695-1

Security update for nodejs22

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2647-1

Security update for nodejs22

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21236-1

Security update for nodejs24

2 месяца назад

Уязвимостей на страницу