← Vulnerability feed

Vulnerability record · CVE-2026-1525 · published 12 March 2026

CVE-2026-1525: Nodejs undici http request smuggling vulnerability

Nodejs · Undici

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: * Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays * Applications that accept user-controlled header names without case-normalization Potential consequences: * Denial of Service: Strict HTTP parsers (proxies, servers) will reject requests with duplicate Content-Length headers (400 Bad Request) * HTTP Request Smuggling: In deployments where an intermediary and backend interpret duplicate headers inconsistently (e.g., one uses the first value, the other uses the last), this can enable request smuggling attacks leading to ACL bypass, cache poisoning, or credential hijacking

9.8 CVSS 3.1 Critical EPSS 0.49% · top 60.1% CWE-444 · HTTP request smuggling
9.8CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: * Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays * Applications that accept user-controlled header names without case-normalization Potential consequences: * Denial of Service: Strict HTTP parsers (proxies, servers) will reject requests with duplicate Content-Length headers (400 Bad Request) * HTTP Request Smuggling: In deployments where an intermediary and backend interpret duplicate headers inconsistently (e.g., one uses the first value, the other uses the last), this can enable request smuggling attacks leading to ACL bypass, cache poisoning, or credential hijacking

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1525 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-35949Nodejs undici server-side request forgery (ssrf) vulnerabilityundici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes…EPSS 1.8%9.1CVE-2026-84961Nodejs undici improper certificate validation vulnerabilityundici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Bec…EPSS 0.25%9.1CVE-2026-13697Nodejs undici information exposure vulnerabilityundici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…EPSS 0.57%8.8CVE-2026-6734Nodejs undici origin validation error vulnerabilityImpact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches…EPSS 0.39%8.2CVE-2026-84933Nodejs undici information exposure vulnerabilityundici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that …EPSS 0.34%7.5CVE-2026-19534Nodejs undici unchecked return value vulnerabilityundici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client ne…EPSS 0.39%7.5CVE-2026-85014Nodejs undici vulnerabilityundici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close…EPSS 0.54%7.5CVE-2026-14643Nodejs undici interpretation conflict vulnerabilityundici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. I…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2026-1525), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.