CVE-2022-35948
published 2022-08-15CVE-2022-35948: undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.27%
67.7th percentile
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-undici | < node-undici 5.8.2+dfsg1+~cs18.9.18.1-1 (bookworm) | node-undici 5.8.2+dfsg1+~cs18.9.18.1-1 (bookworm) |
| nodejs | undici | < 6.28.0 | 6.28.0 |
| nodejs | undici | < 5.8.2 | 5.8.2 |
| nodejs | undici | >= 0 < 5.8.2 | 5.8.2 |
| nodejs | undici | >= 7.0.0 < 7.29.0 | 7.29.0 |
| nodejs | undici | >= 8.0.0 < 8.9.0 | 8.9.0 |
| undici | undici | < 6.28.0 | 6.28.0 |
| undici | undici | >= 0 < 6.28.0 | 6.28.0 |
| undici | undici | >= 7.0.0 < 7.29.0 | 7.29.0 |
| undici | undici | >= 7.0.0 < 7.29.0 | 7.29.0 |
| undici | undici | >= 8.0.0 < 8.9.0 | 8.9.0 |
| undici | undici | >= 8.0.0 < 8.9.0 | 8.9.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undici: undici: HTTP header injection via unvalidated blob-like body type property
vendor_redhat·2026-07-29·CVSS 5.3
CVE-2026-15157 [MEDIUM] CWE-93 undici: undici: HTTP header injection via unvalidated blob-like body type property
undici: undici: HTTP header injection via unvalidated blob-like body type property
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob sha
Red Hat
nodejs: undici vulnerable to CRLF via content headers
vendor_redhat·2022-08-09·CVSS 5.3
CVE-2022-35948 [MEDIUM] CWE-93 nodejs: undici vulnerable to CRLF via content headers
nodejs: undici vulnerable to CRLF via content headers
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
A
Debian
CVE-2022-35948: node-undici - undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]`...
vendor_debian·2022·CVSS 5.3
CVE-2022-35948 [MEDIUM] CVE-2022-35948: node-undici - undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]`...
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
Scope: local
bookworm: resolved (fixed in 5.8.2+dfsg1+~cs1
GHSA
undici vulnerable to CRLF Injection via blob-like body 'type' property
ghsa·2026-08-03·CVSS 5.3
CVE-2026-15157 [MEDIUM] CWE-93 undici vulnerable to CRLF Injection via blob-like body 'type' property
undici vulnerable to CRLF Injection via blob-like body 'type' property
### Impact
When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.
The vulnerable branch in `lib/dispatcher/client-h1.js` pushes `body.type` directly into the outgoing headers with no validation, while every other header path in undici goes through `isValidHeaderValue()`:
```javascript
} else if (util.isBlobLike(body) && request.contentType == null && body.type) {
headers.push('content-type', body.type) // bypasses isValidHeaderValue()
}
```
T
GHSA
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
ghsa·2022-08-18
CVE-2022-35948 [MEDIUM] CWE-74 Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
### Impact
`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header.
Example:
```
import { request } from 'undici'
const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1'
await request('http://localhost:3000, {
method: 'GET',
headers: {
'content-type': unsanitizedContentTypeInput
},
})
```
The above snippet will perform two requests in a single `request` API call:
1) `http://localhost:3000/`
2) `http://localhost:3000/foo2`
### Patches
This issue was patched in Undici v5.8.1
### Workarounds
Sanitize input when sending content-type headers using user input.
## For more information
OSV
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
osv·2022-08-18
CVE-2022-35948 [MEDIUM] Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
### Impact
`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header.
Example:
```
import { request } from 'undici'
const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1'
await request('http://localhost:3000, {
method: 'GET',
headers: {
'content-type': unsanitizedContentTypeInput
},
})
```
The above snippet will perform two requests in a single `request` API call:
1) `http://localhost:3000/`
2) `http://localhost:3000/foo2`
### Patches
This issue was patched in Undici v5.8.1
### Workarounds
Sanitize input when sending content-type headers using user input.
## For more information
OSV
CVE-2022-35948: undici is an HTTP/1
osv·2022-08-15·CVSS 5.3
CVE-2022-35948 [MEDIUM] CVE-2022-35948: undici is an HTTP/1
undici is an HTTP/1.1 client, written from scratch for Node.js.`=< [email protected]` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput = 'application/json\r\n\r\nGET /foo2 HTTP/1.1' await request('http://localhost:3000, { method: 'GET', headers: { 'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet will perform two requests in a single `request` API call: 1) `http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was patched in Undici v5.8.1. Sanitize input when sending content-type headers using user input as a workaround.
No detection rules found.
No public exploits indexed.
https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80https://github.com/nodejs/undici/releases/tag/v5.8.2https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80https://github.com/nodejs/undici/releases/tag/v5.8.2https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3
2022-08-15
Published