THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m8rv-5g2x-5cg5 (medium) — undici vulnerable to CRLF Injection via blob-like body 'type' property

[GHSA] GHSA-m8rv-5g2x-5cg5 (medium) — undici vulnerable to CRLF Injection via blob-like body 'type' property

medgithub_advisoriesPublished 2026-08-03

GHSA-m8rv-5g2x-5cg5 Severity: medium CVE: CVE-2026-15157

undici vulnerable to CRLF Injection via blob-like body 'type' property

### Impact

When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via `request()`, `stream()`, `pipeline()`, or `dispatch()`) with a `.type` derived from untrusted input, an attacker can inject CRLF sequences (`\r\n`) to append arbitrar

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m8rv-5g2x-5cg5