Matteo Collina[verified]@matteocollinaPatch
A high‑severity SOCKS5 TLS bypass (CVE‑2026‑9697) that permits MITM by ignoring TLS settings was identified, with fixes released in ProxyAgent v7.28.0 and v8.5.0.
Daily CyberSecurity@the_yellow_fallPatch
Two new CVEs affecting the undici Node.js HTTP client are disclosed, and users are urged to update the package to mitigate the vulnerabilities.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE‑2026‑9697, detailing a TLS configuration bypass in Undici ProxyAgent when using SOCKS5 proxy URIs.
Infoflowcloud@infoflowcloudDisclosure
The tweet outlines the impact of CVE‑2026‑9697, explaining how ProxyAgent mishandles requestTls with SOCKS5, but provides no proof‑of‑concept, exploit code, patch info, or evidence of active exploitation.
CVE@CVEnewDisclosure
The CVE describes a flaw where undici’s ProxyAgent ignores the requestTls option for SOCKS5 URIs, potentially disrupting HTTPS connections.
Ulises Gascón@kom_256Patch
This post announces a high‑severity fix for CVE‑2026‑9697 in undici, describing a TLS certificate validation bypass vulnerability and providing a link to the GitHub advisory.