An HTTP/1.1 client, written from scratch for Node.js
100%
Total Score
100
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-936878 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. undici is vulnerable to Denial of Service (DoS) in versions 8.3.0 - 8.6.0. | 8.3.0 - 8.6.0 | Low |
AIKIDO-2026-145478 undici is vulnerable to Denial of Service (DoS) in versions 6.17.0 - 6.25.0, 7.0.0 - 7.27.2 and 8.0.0 - 8.4.1. | 6.17.0 - 6.25.07.0.0 - 7.27.28.0.0 - 8.4.1 | High |
CVE-2026-11525 undici is vulnerable to Permissive List of Allowed Inputs in versions 0.0.0 - 6.27.0, 7.0.0 - 7.28.0 and 8.0.0 - 8.5.0. | 0.0.0 - 6.27.07.0.0 - 7.28.08.0.0 - 8.5.0 | Low |
CVE-2026-6734 undici is vulnerable to Origin Validation Error in versions 7.23.0 - 7.28.0 and 8.0.0 - 8.2.0. | 7.23.0 - 7.28.08.0.0 - 8.2.0 | High |
CVE-2026-6733 undici is vulnerable to Time-of-check Time-of-use (TOCTOU) Race Condition in versions 0.0.0 - 6.27.0, 7.0.0 - 7.28.0 and 8.0.0 - 8.5.0. | 0.0.0 - 6.27.07.0.0 - 7.28.08.0.0 - 8.5.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant