CVE-2025-47279
LOW3.1EPSS 0.05%undici Denial of Service attack via bad certificate data
發布日:2025/5/15修改日:2026/2/6
描述
### Impact Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. ### Patches This has been patched in https://github.com/nodejs/undici/pull/4088. ### Workarounds If a webhook fails, avoid keep calling it repeatedly. ### References Reported as: https://github.com/nodejs/undici/issues/3895
受影響套件(2)
- Debian/node-undicifrom 0
- npm/undicifrom 0, < 5.29.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-47279
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2025-47279
- PATCHhttps://github.com/nodejs/undici
- WEBhttps://github.com/nodejs/undici/commit/f317618ec28753a4218beccea048bcf89c36db25
- WEBhttps://github.com/nodejs/undici/issues/3895
- WEBhttps://github.com/nodejs/undici/pull/4088
- WEBhttps://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3