THREAT OPS › Threat News › [GHSA] GHSA-m8rv-5g2x-5cg5 (medium) — undici vulnerable to CRLF Injection via blob-like body 'type' property
[GHSA] GHSA-m8rv-5g2x-5cg5 (medium) — undici vulnerable to CRLF Injection via blob-like body 'type' property
GHSA-m8rv-5g2x-5cg5 Severity: medium CVE: CVE-2026-15157
undici vulnerable to CRLF Injection via blob-like body 'type' property
### Impact
When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrar
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-15157cve
- CVE-2022-35948cve
- CVE-2026-1527cve
Original source: https://github.com/advisories/GHSA-m8rv-5g2x-5cg5