Matteo Collina[verified]@matteocollinaDisclosure
CVE-2026-6733 is a low‑severity keep‑alive response queue poisoning vulnerability that allows a malicious upstream to inject responses onto idle sockets; the post provides technical details but no PoC, exploit, active exploitation claim, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-6733, detailing a response queue poisoning flaw in the Undici HTTP/1.1 client on keep‑alive sockets, without further information on PoC, exploitation, or mitigation.
CVE@CVEnewDisclosure
Undici's HTTP/1.1 client has a response queue poisoning flaw on reused keep‑alive sockets, allowing attacker‑controlled upstream servers to inject unsolicited responses (CVE-2026-6733).
Ulises Gascón@kom_256Patch
A low‑severity patch for undici is released, addressing CVE‑2026‑6733—a vulnerability involving HTTP response queue poisoning via keep‑alive socket reuse—and links to the relevant GitHub advisory.