CVE-2026-1525Patch(nodejs / undici)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: * Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays * Applications that accept user-controlled header names without case-normalization Potential consequences: * Denial of Service: Strict HTTP parsers (proxies, servers) will reject requests with duplicate Content-Length headers (400 Bad Request) * HTTP Request Smuggling: In deployments where an intermediary and backend interpret duplicate headers inconsistently (e.g., one uses the first value, the other uses the last), this can enable request smuggling attacks leading to ACL bypass, cache poisoning, or credential hijacking

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-12: 3Mentions · 2026-05-05: 1Mentions · 2026-09-09: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-09-09: 1Technical Details · 2026-03-12: 3Technical Details · 2026-05-05: 103-1205-0509-09
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure2Patch1
2026-05-051
Patch1
2026-09-091
Patch1
Full discourse5 posts
  • Repojournal@repojournal
    Patch

    Cline collapses the last lingering undici.29.0 copy onto 7.x to close CVE-2026-1525, a residual of an earlier fix. The root override pins undici to ">=7.29.0 <8", killing the nested dependency from dify-ai-provider. If your lockfile still dragged 5.x around, it's gone now. The desktop sidecar gets a deterministic fix for the doubled text and missing rows in the live stream. The observer stream now gates on ClineCore's subscription, replacing the timer-based dedupe. Boot-id handling stays. OpenHands switches issue readiness type detection from label to body. The bug/enhancement criteria stay unchanged, tests pass: 89. langchain-openai hits 1.6.1, adding Azure AD auth support with OpenAI 3.8. Also a bump to max_completion_tokens in the cache breakpoint integration test. Cline's webview learns to flag attached images a selected model can't use and offers a model switch. undici 5.x's reign in Cline might be over. #AIAgents https://repojournal.com/showcase/ai-agents/2026-09-09/cline-collapses-lingering-undici-5-x-to-fix-cve-2026-1525

    Post summary

    The article describes a dependency override that resolves CVE-2026-1525 in the Cline project, effectively patching the vulnerability without mentioning active exploitation or a proof of concept.

    0304082
    438 followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in undici@7.24.0 just released! Patches CVE-2026-1525 — vulnerable to Inconsistent interpretation of HTTP requests (request/response smuggling class issue). https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm

    Post summary

    The text announces a medium‑severity security fix for [email protected] that addresses CVE‑2026‑1525, a request/response smuggling issue.

    00011123
    5.6K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 43 and 44 ship Node.js 20 with multiple DoS flaws CVE-2026-21717, CVE-2026-21714, CVE-2026-1525, CVE-2026-1526, fixed in urgent 20.20.2 update. https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-nodejs-20-affe-ffaf0480

    Post summary

    Fedora 43 and 44 ship Node.js 20 with several DoS vulnerabilities, but an urgent update (20.20.2) has been released to fix them.

    0010050
    181 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1525 Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces … https://www.cve.org/CVERecord?id=CVE-2026-1525

    Post summary

    The post discloses that Undici’s handling of duplicate HTTP Content‑Length headers, including case variants, introduces a vulnerability, but no POC, exploit, patch, or active usage is reported.

    00000106
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1525 HTTP Request Smuggling Vulnerability in Undici via Duplicate Content-Length Headers https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1525

    Post summary

    The post discloses an HTTP request smuggling flaw in Undici caused by duplicate Content-Length headers (CVE‑2026‑1525), with no evidence of exploitation or patches provided.

    0000023
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more