CVE-2026-1525
Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire.
Who is impacted:
Potential consequences:
Detalles técnicos trazas, registros y código del informe original
* Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays * Applications that accept user-controlled header names without case-normalization * Denial of Service: Strict HTTP parsers (proxies, servers) will reject requests with duplicate Content-Length headers (400 Bad Request) * HTTP Request Smuggling: In deployments where an intermediary and backend interpret duplicate headers inconsistently (e.g., one uses the first value, the other uses the last), this can enable request smuggling attacks leading to ACL bypass, cache poisoning, or credential hijacking
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1499.004Application or System Exploitationimpact70 % - Impacto secundario
T1565.002Transmitted Data Manipulationimpact65 %
AV:N/AC:L/PR:N indica aplicación expuesta en red (T1190). Los impactos son DoS por rechazo de parsers (T1499.004), manipulación de caché/ACL mediante request smuggling (T1565.002) y bypass de proxies intermediarios (T1090).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-444
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-1525",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-1525",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-12T20:44:24.555703Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"affectedData": [
{
"repo": "https://github.com/nodejs/undici/",
"vendor": "undici",
"product": "undici",
"versions": [
{
"status": "affected",
"version": "< 6.24.0; 7.0.0 < 7.24.0"
},
{
"status": "unaffected",
"version": "6.24.0: 7.24.0"
}
],
"packageName": "undici",
"collectionURL": "https://github.com/nodejs/undici/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-12T20:16:02.670",
"references": [
{
"url": "https://cna.openjsf.org/security-advisories.html",
"tags": [
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://cwe.mitre.org/data/definitions/444.html",
"tags": [
"Technical Description"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxm",
"tags": [
"Mitigation",
"Vendor Advisory"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://hackerone.com/reports/3556037",
"tags": [
"Permissions Required"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
},
{
"url": "https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6",
"tags": [
"Technical Description"
],
"source": "ce714d77-add3-4f53-aff5-83d477b104bb"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "ce714d77-add3-4f53-aff5-83d477b104bb",
"description": [
{
"lang": "en",
"value": "CWE-444"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire.\n\nWho is impacted:\n\n * Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays\n * Applications that accept user-controlled header names without case-normalization\n\n\nPotential consequences:\n\n * Denial of Service: Strict HTTP parsers (proxies, servers) will reject requests with duplicate Content-Length headers (400 Bad Request)\n * HTTP Request Smuggling: In deployments where an intermediary and backend interpret duplicate headers inconsistently (e.g., one uses the first value, the other uses the last), this can enable request smuggling attacks leading to ACL bypass, cache poisoning, or credential hijacking"
},
{
"lang": "es",
"value": "Undici permite encabezados HTTP Content-Length duplicados cuando se proporcionan en un array con nombres que varían en mayúsculas/minúsculas (p. ej., Content-Length y content-length). Esto produce solicitudes HTTP/1.1 malformadas con múltiples valores Content-Length conflictivos en la red.\n\nQuiénes son los afectados:\n\n * Aplicaciones que utilizan undici.request(), undici.Cliente, o APIs de bajo nivel similares con encabezados pasados como arrays planos\n * Aplicaciones que aceptan nombres de encabezado controlados por el usuario sin normalización de mayúsculas/minúsculas\n\nPosibles consecuencias:\n\n * Denegación de Servicio: Analizadores HTTP estrictos (proxies, servidores) rechazarán las solicitudes con encabezados Content-Length duplicados (400 Solicitud Incorrecta)\n * Contrabando de Solicitudes HTTP: En implementaciones donde un intermediario y un backend interpretan encabezados duplicados de manera inconsistente (p. ej., uno usa el primer valor, el otro usa el último), esto puede habilitar ataques de contrabando de solicitudes que conducen a la omisión de ACL, envenenamiento de caché o secuestro de credenciales"
}
],
"lastModified": "2026-06-17T10:15:59.927",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "C08CE582-019D-4A06-910A-6010C2D6EF4F",
"versionEndExcluding": "6.24.0"
},
{
"criteria": "cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "F016E7D9-C45A-4DEF-9AD8-F0581AF5E509",
"versionEndExcluding": "7.24.0",
"versionStartIncluding": "7.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ce714d77-add3-4f53-aff5-83d477b104bb"
}