Matteo Collina[verified]@matteocollinaPatch
The text discloses CVE-2026-6734, explaining that a connection‑pool reuse flaw caused cross‑origin routing, and it notes the patch available in versions 7.28.0 and 8.2.0.
Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersDisclosure
The post announces CVE‑2026‑6734, describing a cross‑origin request routing flaw that could leak credentials and allow HTTPS downgrades, with a CVSS score of 7.5, but provides no PoC, exploit code, active exploitation evidence, or patch information.
Daily CyberSecurity@the_yellow_fallPatch
The tweet announces four undici CVEs affecting the Node.js HTTP client and urges users to update the library immediately, implying a patch is available.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A headline indicates a cross‑origin request routing vulnerability (CVE-2026-6734) in the Undici Socks5ProxyAgent, offering minimal technical detail without exploitation or remediation information.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑6734, detailing a connection‑pool reuse flaw in undici’s Socks5ProxyAgent, but offers no PoC, exploit, patch, or evidence of active attacks.
CVE@CVEnewDisclosure
The text links to CVE‑2026‑6734, describing a connection‑pool reuse flaw in undici’s Socks5ProxyAgent that lacks origin verification. No PoC, exploit, patch, or active exploitation is mentioned.
Ulises Gascón@kom_256Patch
Node.js "undici" package releases version 7.26.0 and 8.2.0 to patch CVE‑2026‑6734, which could allow cross‑origin request routing through reused SOCKS5 proxies. The advisory link provides further vendor details.