CVE-2026-15157: undici vulnerable to CRLF Injection via blob-like body 'type' property

Published Jul 29, 2026
·
Updated

Impact

When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via request(), stream(), pipeline(), or dispatch()) with a .type derived from untrusted input, an attacker can inject CRLF sequences (\r\n) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.

The vulnerable branch in lib/dispatcher/client-h1.js pushes body.type directly into the outgoing headers with no validation, while every other header path in undici goes through isValidHeaderValue():

javascript } else if (util.isBlobLike(body) && request.contentType == null && body.type) { headers.push('content-type', body.type) // bypasses isValidHeaderValue() }

The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled .type. Native Blob is safe because its constructor strips CRLF from .type. fetch() is unaffected because it validates via the Headers class. Ecosystem consumers that build duck-typed blob shapes from user input include form-data-encoder, formdata-polyfill, and formdata-node.

Same defect class as CVE-2022-35948 (explicit content-type sink, fixed in undici 5.8.2) and CVE-2026-1527 (upgrade option sink, fixed in 6.24.0 / 7.24.0), both closed by adding isValidHeaderValue() on their respective sinks. This branch was missed.

Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.

Workarounds

- Set an explicit, validated content-type header on the request options (skips the vulnerable branch). - Use a native Blob (or fetch-blob) instead of a hand-rolled duck-typed object. - Reject control characters in the MIME type before assigning it to .type. - Use fetch() instead of the non-fetch APIs.

Other sources

undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request, stream, pipeline, or dispatch) whose type is derived from untrusted input allows an attacker to inject CRLF sequences and append arbitrary HTTP headers, potentially smuggling a second request past the upstream. Native Blob objects are safe because their constructor strips CRLF from the type, and fetch is unaffected because it validates headers, but ecosystem libraries that build duck-typed blob shapes from user input can reach the vulnerable path. This is the same defect class as CVE-2022-35948 and CVE-2026-1527, on a header sink that the earlier fixes did not cover. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

MITRE

undici vulnerable to CRLF Injection via blob-like body 'type' property

Microsoft

Affected Software

8 affected componentsFixes available
undici undici>=0<6.28.0, >=7.0.0<7.29.0, >=8.0.0<8.9.0
npm/undici>=8.0.0<8.9.0
8.9.0
npm/undici>=7.0.0<7.29.0
7.29.0
npm/undici<6.28.0
6.28.0
Nodejs Undici Node.js<6.28.0
Nodejs Undici Node.js>=7.0.0<7.29.0
Nodejs Undici Node.js>=8.0.0<8.9.0
Microsoft azl3 nodejs 24.18.1-1<24.18.1-2
24.18.1-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.9.0
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.0
  3. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 6.28.0
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 24.18.1-2
  5. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 6.28.0
  6. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.0
  7. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.9.0
  8. Configuration

    Set an explicit, validated `content-type` header in the request options so the dispatcher skips the vulnerable branch that uses `body.type`.

    Undici HTTP/1.1 request options content-type header = explicit, validated value
  9. Configuration

    Reject control characters in the MIME type before assigning it to `.type` on any duck-typed blob-like object passed to undici.

    Undici (MIME type handling in application) MIME type (body.type) = reject control characters (CR/LF)
  10. Compensating control

    Avoid passing duck-typed blob-like objects whose `.type` is derived from untrusted input (e.g., from `form-data-encoder`, `formdata-polyfill`, or `formdata-node`). Use a native `Blob` (constructor strips CRLF) instead.

  11. Compensating control

    Use `fetch()` instead of undici non-`fetch` APIs (fetch path validates headers via the `Headers` class).

  12. Compensating control

    Use a native `Blob` (or `fetch-blob`) instead of a hand-rolled duck-typed object.

Event History

Jul 29, 2026
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Aug 3, 2026
Advisory Published
via GitHub·07:33 PM
Data Sourced
via GitHub·07:33 PM
DescriptionSeverityWeaknessAffected Software
Aug 7, 2026
Data Sourced
via Microsoft·08:16 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:16 AM
Affected Software
Updated
via Microsoft·08:16 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15157?

The severity of CVE-2026-15157 is rated as medium with a score of 4.2.

2

How do I fix CVE-2026-15157?

To fix CVE-2026-15157, upgrade the undici package to version 6.28.0 or above, or to versions 7.29.0 and above.

3

What vulnerability does CVE-2026-15157 describe?

CVE-2026-15157 describes a CRLF Injection vulnerability caused by the lack of validation for the type property of a blob-like request body.

4

Which versions of undici are affected by CVE-2026-15157?

CVE-2026-15157 affects undici versions prior to 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0.

5

What is the potential impact of CVE-2026-15157?

The potential impact of CVE-2026-15157 includes the ability of attackers to exploit CRLF Injection via crafted body requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203