CVE-2026-6734

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/06/2026
Last modified:
30/07/2026

Description

Impact:<br /> When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool&amp;#39;s origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination.<br /> <br /> This causes cross-origin request routing: credentials and request data intended for origin B are sent to origin A, responses from the wrong origin are trusted, and HTTPS requests may be silently downgraded to HTTP.<br /> <br /> Impacted users are applications that use Socks5ProxyAgent (directly or via setGlobalDispatcher) and make requests to more than one origin.<br /> <br /> This was introduced in undici 7.23.0 via PR #4385 and affects all versions through 8.1.0.<br /> <br /> Patches:<br /> Upgrade to undici v7.26.0 or v8.2.0.<br /> <br /> Workarounds:<br /> Use a separate Socks5ProxyAgent instance per origin, or avoid using Socks5ProxyAgent with multiple origins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 7.23.0 (including) 7.28.0 (excluding)
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 8.0.0 (including) 8.2.0 (excluding)