Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0633 | Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici. |
Github GHSA |
GHSA-5r9g-qh6m-jxff | CRLF Injection in Nodejs ‘undici’ via host |
Mon, 10 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-10T21:10:26.495Z
Reserved: 2023-01-19T21:12:31.361Z
Link: CVE-2023-23936
Updated: 2024-08-02T10:49:07.624Z
Status : Modified
Published: 2023-02-16T18:15:10.877
Modified: 2024-11-21T07:47:08.223
Link: CVE-2023-23936
OpenCVE Enrichment
No data.
EUVD
Github GHSA