undici is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection')
59
Medium Risk
undici's Set-Cookie parser percent-decodes cookie values with qsUnescape, turning encoded sequences such as %0D%0A, %00, %3B, and %3D into their literal bytes, even though RFC 6265 specifies no decoding. An application that parses a Set-Cookie header and forwards the parsed value into one of its own response headers can be tricked by a malicious upstream into injecting carriage-return and line-feed bytes and adding arbitrary Set-Cookie, Location, or Cache-Control headers. This enables HTTP response header injection leading to session fixation, open redirect, or cache poisoning. The fix stops percent-decoding cookie values during parsing.
You are affected if you are using a version that falls within the vulnerable range.
undici is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 6.0.0 - 6.25.0, 7.0.0 - 7.27.2 and 8.0.0 - 8.4.1.
Upgrade the undici library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant