[Git][security-tracker-team/security-tracker][master] Add new batch of node-undici issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 5 10:15:34 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3f67fab2 by Salvatore Bonaccorso at 2026-09-05T11:15:09+02:00
Add new batch of node-undici issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -319,17 +319,23 @@ CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-
CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
NOT-FOR-US: fastify/middie
CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm
CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v
CVE-2026-85014 (undici's experimental WebSocketStream client crashes the whole Node.js ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
CVE-2026-85008 (undici's cache interceptor documents that only safe HTTP methods are c ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv
CVE-2026-84961 (undici's BalancedPool constructor passes its entire options object thr ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3
CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
CVE-2026-84937 (The Video Player for YouTube WordPress plugin before 2.1.0 does not p ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84936 (The EmbedPress WordPress plugin before 4.6.4 does not have proper aut ...)
@@ -339,7 +345,8 @@ CVE-2026-84935 (The HT Menu WordPress plugin before 1.2.7 does not perform any
CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform a capa ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j
CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84930 (The CatFolders Document Gallery & PDF Library WordPress plugin before ...)
@@ -357,7 +364,8 @@ CVE-2026-84898 (The Eventin WordPress plugin before 4.1.21 does not properly va
CVE-2026-84896 (The King Addons for Elementor WordPress plugin before 51.1.77 does no ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm
CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84504 (fastify versions before 5.12.2 treat the object resolved by a successf ...)
@@ -683,7 +691,8 @@ CVE-2026-19649 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user ...)
NOT-FOR-US: IBM
CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5
CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
NOT-FOR-US: IBM
CVE-2026-19305 (IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to ...)
@@ -735,7 +744,8 @@ CVE-2026-18658 (IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.1
CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to ...)
NOT-FOR-US: IBM
CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r
CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context ...)
NOT-FOR-US: IBM
CVE-2026-18486 (IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a ...)
@@ -753,7 +763,8 @@ CVE-2026-18198 (Improper neutralization of special elements used in an SQL comma
CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipula ...)
NOT-FOR-US: IBM
CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
- TODO: check
+ - node-undici <unfixed>
+ NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x
CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
NOT-FOR-US: IBM
CVE-2026-18076 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f67fab2d2f89af1b8a505ddc8a8faf900fc6aab
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3f67fab2d2f89af1b8a505ddc8a8faf900fc6aab
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/f3aeb110/attachment.htm>
More information about the debian-security-tracker-commits
mailing list