CVE-2026-1527General(nodejs / undici)

LOWCVSS 4.6 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Memcached, Elasticsearch) The vulnerability exists because undici writes the upgrade value directly to the socket without validating for invalid header characters: // lib/dispatcher/client-h1.js:1121 if (upgrade) { header += `connection: upgrade\r\nupgrade: ${upgrade}\r\n` }

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-12: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 203-12
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-1527 ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrar… https://www.cve.org/CVERecord?id=CVE-2026-1527

    Post summary

    The excerpt outlines a CRLF injection flaw in client.request()'s upgrade option, providing minimal technical details without indicating a PoC, exploit code, patch, or active exploitation.

    0000097
    56.7K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in undici@7.24.0 just released! Patches CVE-2026-1527 — vulnerable to CRLF injection via the upgrade option. https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvq

    Post summary

    A medium‑severity patch for undici 7.24.0 addresses CVE‑2026‑1527, a CRLF injection flaw in the upgrade option; the advisory confirms the fix but no exploits or real‑world attacks are reported.

    00000114
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more