Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36716
HistoryAug 15, 2022 - 3:46 p.m.

CRLF Injection

2022-08-1515:46:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
25
undici
crlf injection
vulnerability
content-type
api call

0.001 Low

EPSS

Percentile

34.1%

Undici is is vulnerable to CRLF injection. The vulnerability is due to improper request header content-type sanitization in lib/core/request.js. An attacker can exploit this vulnerability to preform two requests in a single API call.