Vulnerabilities/

undici Denial of Service attack via bad certificate data

Severity:
Low

Description

Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.

Recommendation

Update the undici package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
undici
Anything's wrong? Let us know Last updated on May 16, 2025

This issue is available in SmartScanner Professional

See Pricing