CVE-2025-47279

LOW3.1EPSS 0.05%

undici Denial of Service attack via bad certificate data

Published: 5/15/2025Modified: 2/6/2026
Also known as:GHSA-cxrh-j4jr-qwg3CGA-jqp6-v36j-j5g7

Description

### Impact Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. ### Patches This has been patched in https://github.com/nodejs/undici/pull/4088. ### Workarounds If a webhook fails, avoid keep calling it repeatedly. ### References Reported as: https://github.com/nodejs/undici/issues/3895

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW3.1CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

References (7)