undici is vulnerable to Prototype Pollution
33
Low Risk
Affected versions of this package are affected by a prototype pollution vulnerability due to insufficient validation of object property names when processing user-controlled data. Crafted input containing special keys such as __proto__, constructor, or prototype could modify the prototype of internal objects when merged, potentially influencing application behavior or enabling further attacks depending on how the polluted objects are used. The issue is addressed by preventing prototype-related keys from being incorporated into internal objects.
You are affected if you are using a version which is within vulnerability ranges.
undici is vulnerable to Prototype Pollution in versions 2.0.2 - 7.22.0.
Upgrade the undici library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant