undici 8.10.2 appears to be a healthy, mature dependency with a long release history, frequent recent releases, stable versioning, no registry deprecation, active and unarchived source maintenance, broad contributor participation, and organization backing from Node.js. It is licensed, typed, minimally dependent at runtime, published with npm provenance, and supported by extensive repository documentation, tests, security scanning, and a security policy. The prepare lifecycle script and a small number of workflows without top-level permissions warrant routine review, but the available evidence does not indicate a material maintenance or transparency concern.
96%
Total Score
100
100
100
70
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-54683 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. undici is vulnerable to Uncontrolled Recursion in versions 5.15.0 - 8.10.1. | 5.15.0 - 8.10.1 | Medium |
CVE-2026-15157 undici is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.0 - 6.28.0, 7.0.0 - 7.29.0 and 8.0.0 - 8.9.0. | 0.0.0 - 6.28.07.0.0 - 7.29.08.0.0 - 8.9.0 | Medium |
CVE-2026-14643 undici is vulnerable to Interpretation Conflict in versions 7.0.0 - 7.29.0 and 8.0.0 - 8.9.0. | 7.0.0 - 7.29.08.0.0 - 8.9.0 | Medium |
CVE-2026-16729 undici is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 6.28.0, 7.0.0 - 7.29.0 and 8.0.0 - 8.9.0. | 0.0.0 - 6.28.07.0.0 - 7.29.08.0.0 - 8.9.0 | Medium |
CVE-2026-16728 undici is vulnerable to Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in versions 0.0.0 - 6.28.0, 7.0.0 - 7.29.0 and 8.0.0 - 8.9.0. | 0.0.0 - 6.28.07.0.0 - 7.29.08.0.0 - 8.9.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.