GHSA-m8rv-5g2x-5cg5: CRLF Injection

Published Aug 3, 2026
·
Updated

Impact

When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via request(), stream(), pipeline(), or dispatch()) with a .type derived from untrusted input, an attacker can inject CRLF sequences (\r\n) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.

The vulnerable branch in lib/dispatcher/client-h1.js pushes body.type directly into the outgoing headers with no validation, while every other header path in undici goes through isValidHeaderValue():

javascript } else if (util.isBlobLike(body) && request.contentType == null && body.type) { headers.push('content-type', body.type) // bypasses isValidHeaderValue() }

The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled .type. Native Blob is safe because its constructor strips CRLF from .type. fetch() is unaffected because it validates via the Headers class. Ecosystem consumers that build duck-typed blob shapes from user input include form-data-encoder, formdata-polyfill, and formdata-node.

Same defect class as CVE-2022-35948 (explicit content-type sink, fixed in undici 5.8.2) and CVE-2026-1527 (upgrade option sink, fixed in 6.24.0 / 7.24.0), both closed by adding isValidHeaderValue() on their respective sinks. This branch was missed.

Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.

Workarounds

- Set an explicit, validated content-type header on the request options (skips the vulnerable branch). - Use a native Blob (or fetch-blob) instead of a hand-rolled duck-typed object. - Reject control characters in the MIME type before assigning it to .type. - Use fetch() instead of the non-fetch APIs.

Affected Software

3 affected componentsFixes available
npm/undici>=8.0.0<8.9.0
8.9.0
npm/undici>=7.0.0<7.29.0
7.29.0
npm/undici<6.28.0
6.28.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.9.0
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.0
  3. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 6.28.0
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 6.28.0
  5. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.0
  6. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.9.0
  7. Configuration

    Set an explicit, validated `content-type` header on the request options so the vulnerable branch that does `headers.push('content-type', body.type)` is skipped.

    undici request/dispatcher (HTTP/1.1) request options content-type = explicit validated content-type header (set content-type to a validated value; do not rely on duck-typed body.type)
  8. Configuration

    Reject control characters (e.g., CRLF `\r\n`) in the MIME type before assigning it to the blob-like object's `.type`.

    Application MIME handling MIME type (body.type) = reject control characters
  9. Configuration

    Use `fetch()` rather than undici's non-`fetch` APIs for requests, since `fetch()` validates via the `Headers` class and is unaffected by the vulnerable HTTP/1.1 branch.

    Application request API usage HTTP client API = use fetch() instead of non-fetch APIs
  10. Configuration

    Use a native `Blob` (or `fetch-blob`) instead of a hand-rolled duck-typed blob-like object, because native `Blob` strips CRLF from `.type`.

    Application blob construction body object type = native Blob (or fetch-blob)

Event History

Aug 3, 2026
Advisory Published
via GitHub·07:33 PM
Data Sourced
via GitHub·07:33 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of GHSA-m8rv-5g2x-5cg5?

The severity of GHSA-m8rv-5g2x-5cg5 is medium with a score of 4.2.

2

How do I fix GHSA-m8rv-5g2x-5cg5?

To fix GHSA-m8rv-5g2x-5cg5, ensure that any `.type` derived from untrusted input is properly sanitized before being passed to undici's HTTP dispatcher.

3

What type of vulnerability is GHSA-m8rv-5g2x-5cg5?

GHSA-m8rv-5g2x-5cg5 is a CRLF Injection vulnerability.

4

What software is affected by GHSA-m8rv-5g2x-5cg5?

The vulnerability GHSA-m8rv-5g2x-5cg5 affects the npm package 'undici'.

5

What is the impact of GHSA-m8rv-5g2x-5cg5?

The impact of GHSA-m8rv-5g2x-5cg5 allows an attacker to inject CRLF sequences to append arbitrary HTTP headers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203