Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1240 | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1. |
Github GHSA |
GHSA-m4v8-wqvr-p9f7 | Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline |
Wed, 05 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 13 Feb 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1. | Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1. |
Wed, 18 Dec 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora Nodejs Nodejs undici |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora Nodejs Nodejs undici |
Sat, 14 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat openshift Devspaces |
|
| CPEs | cpe:/a:redhat:openshift_devspaces:3::el8 | |
| Vendors & Products |
Redhat
Redhat openshift Devspaces |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-04T16:11:54.904Z
Reserved: 2024-03-26T12:52:00.934Z
Link: CVE-2024-30260
Updated: 2025-11-04T16:11:54.904Z
Status : Modified
Published: 2024-04-04T16:15:08.877
Modified: 2025-11-04T17:15:50.140
Link: CVE-2024-30260
OpenCVE Enrichment
No data.
EUVD
Github GHSA