org.webjars.npm:undici

Licenses: MIT

Direct Vulnerabilities

Known vulnerabilities in the org.webjars.npm:undici package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Uncaught Exception

[7.12.0,)
  • M
Insufficient Verification of Data Authenticity

[7.12.0,)
  • C
Improper Certificate Validation

[7.27.1,)
  • H
Use of Persistent Cookies Containing Sensitive Information

[7.12.0,)
  • M
Numeric Truncation Error

[7.12.0,)
  • M
HTTP Request Smuggling

[,6.28.1)[7.12.0,)
  • H
Uncaught Exception

[6.23.0,6.28.1)[7.12.0,)
  • H
Allocation of Resources Without Limits or Throttling

[7.16.0,)
  • H
Missing Release of Resource after Effective Lifetime

[7.12.0,)
  • M
Improper Neutralization

[,6.28.0)[7.0.0,7.29.0)[8.0.0,8.9.0)
  • M
HTTP Request Smuggling

[,6.28.0)[7.0.0,7.29.0)[8.0.0,8.9.0)
  • L
CRLF Injection

[,6.28.0)[7.0.0,7.29.0)[8.0.0,8.9.0)
  • H
Information Exposure

[7.0.0,7.29.0)[8.0.0,8.9.0)
  • H
Interpretation Conflict

[7.0.0,7.29.0)[8.0.0,8.9.0)
  • H
Origin Validation Error

[7.27.1,)
  • H
Use of Cache Containing Sensitive Information

[7.12.0,)
  • M
Time-of-check Time-of-use (TOCTOU) Race Condition

[0,)
  • H
Allocation of Resources Without Limits or Throttling

[0,)
  • H
Permissive List of Allowed Inputs

[,6.27.0)[7.0.0,7.28.0)[8.0.0,8.5.0)
  • C
CRLF Injection

[,6.27.0)[7.0.0,7.28.0)[8.0.0,8.5.0)
  • H
Allocation of Resources Without Limits or Throttling

[8.0.0,8.5.0)
  • M
Improper Certificate Validation

[7.23.0,7.28.0)[8.0.0,8.5.0)
  • M
HTTP Request Smuggling

[,7.27.1)
  • H
Uncaught Exception

[,7.27.1)
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

[,7.27.1)
  • H
Uncaught Exception

[,7.27.1)
  • M
CRLF Injection

[,7.27.1)
  • M
Allocation of Resources Without Limits or Throttling

[,7.27.1)
  • L
Missing Release of Memory after Effective Lifetime

[,5.29.0)
  • H
Insecure Randomness

[,7.12.0)
  • L
Improper Authorization

[,5.28.4)
  • L
Improper Access Control

[,5.28.4)
  • L
Permissive Cross-domain Policy with Untrusted Domains

[,5.28.3)
  • L
Information Exposure

[,5.27.0)
  • H
Regular Expression Denial of Service (ReDoS)

[,5.20.0)
  • M
CRLF Injection

[,5.20.0)
  • M
CRLF Injection

[,5.10.0)
  • M
Server-side Request Forgery (SSRF)

[,5.10.0)
  • L
Information Exposure

[,5.10.0)
  • M
CRLF Injection

[,5.10.0)
  • M
Improper Certificate Validation

[4.8.2,5.5.1)

Package versions

20 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
7.27.15 Jun, 2026
  • 2
    C
  • 11
    H
  • 7
    M
  • 1
    L
7.16.018 Dec, 2025
  • 1
    C
  • 13
    H
  • 9
    M
  • 1
    L
7.12.018 Jul, 2025
  • 1
    C
  • 12
    H
  • 9
    M
  • 1
    L
6.29.029 Sep, 2026
  • 0
    C
  • 5
    H
  • 4
    M
  • 0
    L
6.28.15 Sep, 2026
  • 0
    C
  • 5
    H
  • 4
    M
  • 0
    L
6.23.010 Feb, 2026
  • 1
    C
  • 7
    H
  • 7
    M
  • 1
    L
5.29.014 May, 2025
  • 1
    C
  • 6
    H
  • 7
    M
  • 1
    L
5.28.412 Jul, 2024
  • 1
    C
  • 6
    H
  • 7
    M
  • 2
    L
5.28.317 Feb, 2024
  • 1
    C
  • 6
    H
  • 7
    M
  • 4
    L
5.27.223 Nov, 2023
  • 1
    C
  • 6
    H
  • 7
    M
  • 5
    L