The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade undici to version 8.10.2 or higher.
undici is an An HTTP/1.1 client, written from scratch for Node.js
Affected versions of this package are vulnerable to Origin Validation Error leading to cache poisoning in the interceptors.cache() and interceptors.deduplicate() interceptors, which build cache and deduplication keys without the actual destination origin when the dispatcher lacks a single authoritative origin or requests supply their own origin. An attacker who controls responses from one origin can have them returned for requests to a different, trusted origin whose method, path, and relevant headers match, enabling cross-origin information disclosure and persistent cache poisoning such as JWKS poisoning. This requires a cache store or interceptor instance shared across multiple origins, together with a dispatcher that has no single authoritative origin or requests that carry their own origin.
This vulnerability can be avoided by using separate cache stores and interceptor instances per origin rather than sharing them across origins, so requests to different origins cannot share a cache key.