PT-2026-50512 · Npm+1 · Undici+1

·

CVE-2026-6733

·

Published

2026-06-17

·

Updated

2026-09-03

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions undici versions prior to 6.26.0 undici versions prior to 7.28.0 undici versions prior to 8.5.0
Description The HTTP/1.1 client is subject to response queue poisoning when keep-alive sockets are reused. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request has finished. Consequently, when the client sends a subsequent request using that same socket, it incorrectly associates the injected response with the new request, leading to responses being delivered to the wrong requests. This issue requires a compromised or attacker-controlled upstream HTTP/1.1 server and the use of keep-alive connection reuse.
Recommendations Upgrade to version 6.26.0. Upgrade to version 7.28.0. Upgrade to version 8.5.0. As a temporary workaround, disable keep-alive connection reuse by setting the keepAliveTimeout variable to 0 on the Client or Pool.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:35841
ALSA-2026:35842
ALSA-2026:35891
ALSA-2026:35892
ALSA-2026:39868
ALSA-2026:41947
CLEANSTART-2026-KN24948
CLEANSTART-2026-ZJ21676
CVE-2026-6733
ECHO-0ED3-95C6-1C1C
GHSA-35P6-XMWP-9G52
OPENSUSE-SU-2026:11121-1
OPENSUSE-SU-2026:21058-1
OPENSUSE-SU-2026:21236-1
RHSA-2026:35841
RHSA-2026:35842
RHSA-2026:35891
RHSA-2026:35892
RHSA-2026:39868
SUSE-SU-2026:22368-1
SUSE-SU-2026:22565-1
SUSE-SU-2026:2633-1
SUSE-SU-2026:2647-1
SUSE-SU-2026:2695-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Rocky Linux
Undici