CVE-2026-6733Disclosure(nodejs / undici)

LOWCVSS 3.7 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nodejs undici systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • undici

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-17); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
undici

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-17: 2Mentions · 2026-06-18: 2Patch / Workaround · 2026-06-17: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 206-1706-18
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-172
Disclosure1Patch1
2026-06-182
Disclosure2
Full discourse4 posts
  • Matteo Collina@matteocollina
    Disclosure

    🔵 Low: Keep-alive response queue poisoning (CVE-2026-6733). A hostile upstream could inject responses onto idle sockets → wrong response delivered to the wrong request. v6/v7/v8.

    Post summary

    CVE-2026-6733 is a low‑severity keep‑alive response queue poisoning vulnerability that allows a malicious upstream to inject responses onto idle sockets; the post provides technical details but no PoC, exploit, active exploitation claim, or patch information.

    10040824
    57.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6733 Response Queue Poisoning in Undici HTTP/1.1 Client on Keep-Alive Sockets https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6733

    Post summary

    The text announces CVE-2026-6733, detailing a response queue poisoning flaw in the Undici HTTP/1.1 client on keep‑alive sockets, without further information on PoC, exploitation, or mitigation.

    0000045
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6733 Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicite… https://www.cve.org/CVERecord?id=CVE-2026-6733

    Post summary

    Undici's HTTP/1.1 client has a response queue poisoning flaw on reused keep‑alive sockets, allowing attacker‑controlled upstream servers to inject unsolicited responses (CVE-2026-6733).

    00000150
    57.6K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Low-severity security fix in undici (6.26.0, 7.28.0, 8.5.0) just released! Patches CVE-2026-6733. undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse. https://github.com/nodejs/undici/security/advisories/GHSA-35p6-xmwp-9g52

    Post summary

    A low‑severity patch for undici is released, addressing CVE‑2026‑6733—a vulnerability involving HTTP response queue poisoning via keep‑alive socket reuse—and links to the relevant GitHub advisory.

    00000116
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsundici-node.js-

Explore more