Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2026-15157
Published:July 29, 2026
Updated:August 02, 2026
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.
Affected Packages
https://github.com/nodejs/undici.git (GITHUB):
Affected version(s) >=v7.0.0 <v7.29.0
Fix Suggestion:
Update to version v7.29.0
https://github.com/nodejs/undici.git (GITHUB):
Affected version(s) >=v6.21.0 <v6.28.0
Fix Suggestion:
Update to version v6.28.0
https://github.com/nodejs/undici.git (GITHUB):
Affected version(s) >=v8.0.0 <v8.9.0
Fix Suggestion:
Update to version v8.9.0
undici (NPM):
Affected version(s) >=0.1.0 <6.28.0
Fix Suggestion:
Update to version 6.28.0
undici (NPM):
Affected version(s) >=7.0.0 <7.29.0
Fix Suggestion:
Update to version 7.29.0
undici (NPM):
Affected version(s) >=8.0.0 <8.9.0
Fix Suggestion:
Update to version 8.9.0
Do you need more information?
Contact Us
CVSS v4
Base Score:
2.3
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
4.2
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
Improper Neutralization of CRLF Sequences ('CRLF Injection')
EPSS
Base Score:
0.14