Vulnerabilities/

undici before v5.8.0 vulnerable to CRLF injection in request headers

Severity:
Medium

Description

It is possible to inject CRLF sequences into request headers in Undici.

The same applies to path and method

Recommendation

Update the undici package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
undici
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing