Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39307
HistoryFeb 17, 2023 - 3:00 a.m.

CRLF Injection

2023-02-1703:00:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
47
undici
crlf injection
processheader
software vulnerability

EPSS

0.001

Percentile

50.9%

undici is vulnerable to CRLF Injection. The vulnerability exists because the headers.host string does not properly sanitize the HTTP header in the processHeader function in request.js, allowing an attacker to redirect to a malicious URL through a malicious HTTP header.