Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-15389 Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.
Github GHSA Github GHSA GHSA-cxrh-j4jr-qwg3 undici Denial of Service attack via bad certificate data
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 May 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Fri, 16 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 17:30:00 +0000

Type Values Removed Values Added
Description Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak. This has been patched in versions 5.29.0, 6.21.2, and 7.5.0. As a workaound, avoid calling a webhook repeatedly if the webhook fails.
Title undici Denial of Service attack via bad certificate data
Weaknesses CWE-401
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-05-16T13:44:28.438Z

Reserved: 2025-05-05T16:53:10.373Z

Link: CVE-2025-47279

cve-icon Vulnrichment

Updated: 2025-05-15T17:56:23.757Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-15T18:15:38.027

Modified: 2025-05-16T14:43:26.160

Link: CVE-2025-47279

cve-icon Redhat

Severity : Low

Publid Date: 2025-05-15T17:16:02Z

Links: CVE-2025-47279 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-06-23T19:31:58Z