CVE-2022-31150

undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0. Sanitizing all HTTP headers from untrusted sources to eliminate `\r\n` is a workaround for this issue.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
Affected Products (NVD)
VendorProductVersion
nodejsundici
𝑥
< 5.8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-undici
bookworm
5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
fixed
bookworm (security)
5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3
fixed
sid
5.28.4+dfsg1+~cs23.12.11-2
fixed
trixie
5.28.4+dfsg1+~cs23.12.11-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-undici
bionic
dne
focal
dne
jammy
dne
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs16
suse enterprise sap 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise sap 15 SP4
16.17.0-150400.3.6.1
fixed
suse enterprise server 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise server 15 SP4
16.17.0-150400.3.6.1
fixed
nodejs16-devel
suse enterprise sap 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise sap 15 SP4
16.17.0-150400.3.6.1
fixed
suse enterprise server 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise server 15 SP4
16.17.0-150400.3.6.1
fixed
nodejs16-docs
suse enterprise sap 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise sap 15 SP4
16.17.0-150400.3.6.1
fixed
suse enterprise server 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise server 15 SP4
16.17.0-150400.3.6.1
fixed
npm16
suse enterprise sap 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise sap 15 SP4
16.17.0-150400.3.6.1
fixed
suse enterprise server 15 SP3
16.17.0-150300.7.9.1
fixed
suse enterprise server 15 SP4
16.17.0-150400.3.6.1
fixed