cbcvebase.
CVE-2026-6733
published 2026-06-17

CVE-2026-6733: Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an…

PriorityP417low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EPSS
0.23%
13.5th percentile
Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platformautomation-portal
ansible-automation-platformbootc-automation-portal-rhel9
devspacescode-rhel9
devspacesdashboard-rhel9
devspacesopenvsx-rhel9
devspacespluginregistry-rhel9
nodejsnodejs
nodejsundici< 6.27.06.27.0
nodejsundici>= 7.0.0 < 7.28.07.28.0
nodejsundici>= 8.0.0 < 8.5.08.5.0
nodejs_22nodejs
nodejs_24nodejs
odf4ocs-client-console-rhel9
odf4odf-console-rhel9
odf4odf-multicluster-console-rhel9
openshift-pipelinespipelines-console-plugin-pf5-rhel9
openshift-pipelinespipelines-console-plugin-rhel8
openshift-pipelinespipelines-console-plugin-rhel9
openshift4ose-agent-installer-ui-rhel9
openshift4ose-console-rhel9
openshift4ose-monitoring-plugin-rhel9
rhdhrhdh-hub-rhel9
rhoaiodh-dashboard-rhel9
rhoaiodh-mod-arch-automl-rhel9
rhoaiodh-mod-arch-autorag-rhel9

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
cvelistv5v3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.