CVE-2026-9697Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-06-17); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-06-17: 3Mentions · 2026-06-18: 2Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-17: 3Technical Details · 2026-06-18: 206-1706-1806-22
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-173
Disclosure2Patch1
2026-06-182
Disclosure1Patch1
2026-06-221
Patch1
Full discourse6 posts
  • Matteo Collina@matteocollina
    Patch

    🟠 High: SOCKS5 TLS bypass (CVE-2026-9697). ProxyAgent silently dropped `requestTls` over SOCKS5 → your `ca`, `cert`, `rejectUnauthorized`, `servername` were ignored, falling back to the Mozilla bundle. Cert pinning broke = MITM risk. v7/v8. Fixed in 7.28.0 / 8.5.0.

    Post summary

    A high‑severity SOCKS5 TLS bypass (CVE‑2026‑9697) that permits MITM by ignoring TLS settings was identified, with fixes released in ProxyAgent v7.28.0 and v8.5.0.

    10030351
    57.8K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Four undici vulnerabilities (CVE-2026-6734, CVE-2026-9697) affect the Node.js HTTP client, which sees 133M weekly downloads. Update undici now. #undici #NodeJS #npm #SOCKS5 #WebSocket #AppSec #Vulnerability https://securityonline.info/undici-vulnerabilities https://t.co/MIpNFukQaw

    Post summary

    Two new CVEs affecting the undici Node.js HTTP client are disclosed, and users are urged to update the package to mitigate the vulnerabilities.

    01010557
    12.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-9697 TLS Configuration Bypass in Undici ProxyAgent with SOCKS5 Proxy URIs https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-9697

    Post summary

    The text announces CVE‑2026‑9697, detailing a TLS configuration bypass in Undici ProxyAgent when using SOCKS5 proxy URIs.

    0000064
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-9697 Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through th… https://www.cve.org/CVERecord?id=CVE-2026-9697 ----- Traducción: Impacto de CVE-20… http://infoflow.cloud`

    Post summary

    The tweet outlines the impact of CVE‑2026‑9697, explaining how ProxyAgent mishandles requestTls with SOCKS5, but provides no proof‑of‑concept, exploit code, patch info, or evidence of active exploitation.

    0000038
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9697 Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through th… https://www.cve.org/CVERecord?id=CVE-2026-9697

    Post summary

    The CVE describes a flaw where undici’s ProxyAgent ignores the requestTls option for SOCKS5 URIs, potentially disrupting HTTPS connections.

    00000201
    57.6K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 High-severity security fix in undici (7.28.0, 8.5.0) just released! Patches CVE-2026-9697. undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent. https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g

    Post summary

    This post announces a high‑severity fix for CVE‑2026‑9697 in undici, describing a TLS certificate validation bypass vulnerability and providing a link to the GitHub advisory.

    00000103
    5.5K followersView on X

Explore more