undici is vulnerable to Prototype Pollution
33
Low Risk
Affected versions of this package are affected by a prototype pollution vulnerability due to insufficient validation of object property names when processing user-controlled input. Crafted input containing special keys such as __proto__, constructor, or prototype could be merged into internal objects, allowing modification of the object prototype chain. This may influence application behavior or enable further attacks depending on how polluted properties are used. The issue is addressed by preventing prototype-related keys from being incorporated into internal objects.
You are affected if you are using a version which is within vulnerability ranges.
undici is vulnerable to Prototype Pollution in versions 4.0.0 - 7.24.0.
Upgrade the undici library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant