CVE-2026-15157

EUVD-2026-50568
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.
CRLF Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.2 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 9.03%
Affected Products (NVD)
VendorProductVersion
nodejsundici
𝑥
< 6.28.0
nodejsundici
7.0.0 ≤
𝑥
< 7.29.0
nodejsundici
8.0.0 ≤
𝑥
< 8.9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-undici
bookworm
postponed
bookworm (security)
vulnerable
forky
8.9.0+dfsg+~cs3.2.0-1
fixed
sid
8.10.2+dfsg+~cs3.2.2-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-undici
jammy
dne
noble
needs-triage
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
nodejs22
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-debuginfo
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-debugsource
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-devel
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-docs
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-full-i18n
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-libs
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-libs-debuginfo
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-npm
Amazon Linux 2023
1:10.9.8-1.22.23.2.1.amzn2023.0.2
fixed
nodejs24
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-debuginfo
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-debugsource
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-devel
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-docs
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-full-i18n
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-libs
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-libs-debuginfo
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-npm
Amazon Linux 2023
1:11.16.0-1.24.18.1.1.amzn2023.0.2
fixed
v8-12.4-devel
Amazon Linux 2023
3:12.4.254.21-1.22.23.2.1.amzn2023.0.2
fixed
v8-13.6-devel
Amazon Linux 2023
3:13.6.233.17-1.24.18.1.1.amzn2023.0.2
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
nodejs
Azure Linux 3.0
0:24.20.0-1.azl3
fixed