299,751
Total vulnerabilities in the database
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authentication headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
| Software | From | Fixed in |
|---|---|---|
undici
|
- | 5.28.3 |
undici
|
6.0.0 | 6.6.1 |
| nodejs / undici | 6.0.0 | 6.6.1 |
| nodejs / undici | - | 5.28.3 |