Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-6734

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
17/06/2026
Última modificación:
30/07/2026

Descripción

*** Pendiente de traducción *** Impact:<br /> When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool&amp;#39;s origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination.<br /> <br /> This causes cross-origin request routing: credentials and request data intended for origin B are sent to origin A, responses from the wrong origin are trusted, and HTTPS requests may be silently downgraded to HTTP.<br /> <br /> Impacted users are applications that use Socks5ProxyAgent (directly or via setGlobalDispatcher) and make requests to more than one origin.<br /> <br /> This was introduced in undici 7.23.0 via PR #4385 and affects all versions through 8.1.0.<br /> <br /> Patches:<br /> Upgrade to undici v7.26.0 or v8.2.0.<br /> <br /> Workarounds:<br /> Use a separate Socks5ProxyAgent instance per origin, or avoid using Socks5ProxyAgent with multiple origins.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 7.23.0 (incluyendo) 7.28.0 (excluyendo)
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* 8.0.0 (incluyendo) 8.2.0 (excluyendo)