THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-9697 (HIGH 7.4) — Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthor

[NVD] CVE-2026-9697 (HIGH 7.4) — Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthor

lownvdPublished 2026-06-17

CVE-2026-9697 CVSS: 7.4 HIGH Published: 2026-06-17T18:18:06.473

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.

Applications that pin t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-9697