The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsA fix was pushed into the master branch but not yet published.
org.webjars.npm:undici is an An HTTP/1.1 client, written from scratch for Node.js
Affected versions of this package are vulnerable to Missing Release of Resource after Effective Lifetime in the RetryHandler, which can leave a response body pending indefinitely when a retried request receives a non-retryable response after a truncated one. An attacker can accumulate unresolved promises and streams until the client is denied service by running a malicious server that repeatedly returns a non-retryable response following a truncated one, so the original response body never resolves and calls like response.body.text() never complete. This requires the application to retry requests through the RetryHandler, and bodyTimeout does not fire because the orphaned body is never active.
This vulnerability can be avoided by imposing an independent request deadline and destroying the response body when it expires, since bodyTimeout alone does not release the orphaned body.