CVE-2024-24758

LOW

Undici <5.28.2, <6.6 - Auth Bypass

Title source: llm
STIX 2.1

Description

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 3.9
EPSS 0.0028
EPSS Percentile 51.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
nodejs/undici < 5.28.3
npm/undici 0 - 5.28.3npm
Published Feb 16, 2024
Tracked Since Feb 18, 2026