« Volver al listado

CVE-2025-47279

Estado: AplazadaBaja (3.1)—

Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-47279",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-47279",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-15T17:51:54.156281Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nodejs",
          "product": "undici",
          "versions": [
            {
              "status": "affected",
              "version": "< 5.29.0"
            },
            {
              "status": "affected",
              "version": ">= 6.0.0, < 6.21.2"
            },
            {
              "status": "affected",
              "version": ">= 7.0.0, < 7.5.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-05-15T18:15:38.027",
  "references": [
    {
      "url": "https://github.com/nodejs/undici/commit/f317618ec28753a4218beccea048bcf89c36db25",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nodejs/undici/issues/3895",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nodejs/undici/pull/4088",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nodejs/undici/security/advisories/GHSA-cxrh-j4jr-qwg3",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-401"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails."
    },
    {
      "lang": "es",
      "value": "Undici es un cliente HTTP/1.1 para Node.js. En versiones anteriores a la 5.29.0, 6.21.2 y 7.5.0, las aplicaciones que usan undici para implementar un sistema similar a un webhook son vulnerables. Si el atacante configura un servidor con un certificado no válido y logra forzar la aplicación a llamar al webhook repetidamente, puede causar una fuga de memoria. Esto se ha corregido en las versiones 5.29.0, 6.21.2 y 7.5.0. Como solución alternativa, evite llamar a un webhook repetidamente si este falla."
    }
  ],
  "lastModified": "2026-06-17T09:27:39.467",
  "sourceIdentifier": "security-advisories@github.com"
}