Node.js Advisory · May 2026

Node.js Security Advisory: May 2026 Undici CRLF Injection Triage

Triage of Node.js May 2026 release fixing CRLF header injection and SSRF protections in the built-in global fetch / undici client.

4
Vulnerabilities Addressed
1
CRLF / SSRF Vector
7.5
CVSS undici
High
Backend Microservice Priority

Executive Triage und Risikobewertung

Node.js patched CVE-2024-30260 in undici (the backend of globalThis.fetch). Carriage return characters in custom header values were not stripped, enabling HTTP request splitting and SSRF proxy bypass.

Kuratierte Schwachstellen-Triage-Matrix

CVE-Kennung Subsystem / Komponente Auswirkung CVSS Aktive Ausnutzung?
CVE-2024-30260undici / global fetch()CRLF Header Injection & SSRF7.5 HighYES (In-The-Wild)
CVE-2024-30261zlib DecompressionZip Bomb ReDoS6.2 MediumNo
CVE-2024-30262vm ModuleContext Isolation Leak5.8 MediumNo
HERVORGEHOBENE CODE-ANALYSE

Deep Dive: Undici CRLF Injection and SSRF Teardown →

See the JavaScript validation patch in lib/core/request.js disallowing control characters in outgoing HTTP headers.

← Sicherheitsverzeichnis durchsuchen Alle Sicherheitsupdates →