Description
`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6112 | `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server. |
Github GHSA |
GHSA-pgw7-wx7w-2w33 | ProxyAgent vulnerable to MITM |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-03T07:32:56.020Z
Reserved: 2022-06-01T00:00:00.000Z
Link: CVE-2022-32210
No data.
Status : Modified
Published: 2022-07-14T15:15:08.183
Modified: 2024-11-21T07:05:55.847
Link: CVE-2022-32210
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA