CVE-2026-9697: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

Published Jun 17, 2026
·
Updated

Impact

undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.

Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.

Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.

Patches

Upgrade to undici v7.28.0 or v8.5.0.

Workarounds

No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.

Other sources

Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.

Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.

Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.

Patches: Upgrade to undici v7.28.0 or v8.5.0.

Workarounds: No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.

NVD

undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent

Microsoft

Affected Software

9 affected componentsFixes available
npm/undici>=7.23.0<7.28.0, >=8.0.0<8.5.0
npm/undici>=8.0.0<8.5.0
8.5.0
npm/undici>=7.23.0<7.28.0
7.28.0
Microsoft azl3 nodejs 24.14.1-3<24.17.0-1
24.17.0-1
Nodejs Undici Node.js>=7.23.0<7.28.0
Nodejs Undici Node.js>=8.0.0<8.5.0
IBM Maximo Application Suite<=9.2
IBM Maximo Application Suite<=9.1
IBM Maximo Application Suite<=9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.5.0
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.28.0
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 24.17.0-1
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.28.0
  5. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.5.0
  6. Compensating control

    If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead (HTTP-proxy ProxyAgent where requestTls is honored correctly), rather than using undici ProxyAgent/Socks5ProxyAgent over socks5:// or socks://.

Event History

Jun 17, 2026
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
Affected Software
Data Sourced
via Red Hat·07:03 PM
DescriptionSeverityAffected Software
Jun 18, 2026
Advisory Published
via GitHub·02:28 PM
Data Sourced
via GitHub·02:28 PM
DescriptionSeverityWeaknessAffected Software
Jun 27, 2026
Data Sourced
via Microsoft·08:07 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:07 AM
DescriptionSeverity
Aug 3, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
May 9, 58583
Event
via FIRST·12:51 AM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-9697?

CVE-2026-9697 has a severity score of 7.4, classified as high.

2

How does CVE-2026-9697 affect undici's ProxyAgent functionality?

CVE-2026-9697 causes undici's ProxyAgent to drop the requestTls option when used with a SOCKS5 proxy, which may lead to TLS certificate validation bypass.

3

What impact does CVE-2026-9697 have on HTTPS connections?

CVE-2026-9697 allows HTTPS connections to default to Node's trust store, ignoring critical user-provided certificate configurations.

4

How can I mitigate the risks associated with CVE-2026-9697?

To mitigate CVE-2026-9697, avoid using SOCKS5 proxies with undici's ProxyAgent if TLS certificate validation is required.

5

When was CVE-2026-9697 published?

CVE-2026-9697 was published on June 17, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203