REDHAT-BUG-2447144: Medium severity npm/undici vulnerability

Published Mar 12, 2026
·
Updated

Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire.

Who is impacted:

Applications using undici.request(), undici.Client, or similar low-level APIs with headers passed as flat arrays Applications that accept user-controlled header names without case-normalization

Potential consequences:

Denial of Service: Strict HTTP parsers (proxies, servers) will reject requests with duplicate Content-Length headers (400 Bad Request) HTTP Request Smuggling: In deployments where an intermediary and backend interpret duplicate headers inconsistently (e.g., one uses the first value, the other uses the last), this can enable request smuggling attacks leading to ACL bypass, cache poisoning, or credential hijacking

Affected Software

1 affected component
npm/undici

Event History

Mar 12, 2026
Data Sourced
via Red Hat·09:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2447144?

The severity of REDHAT-BUG-2447144 is classified as medium with a score of 4.

2

How do I fix REDHAT-BUG-2447144?

To fix REDHAT-BUG-2447144, ensure that the application using undici does not send duplicate Content-Length headers with case-variant names.

3

What applications are impacted by REDHAT-BUG-2447144?

Applications that use the npm/undici library are impacted by REDHAT-BUG-2447144.

4

What is the main issue described in REDHAT-BUG-2447144?

The main issue in REDHAT-BUG-2447144 is that undici allows duplicate HTTP Content-Length headers, resulting in malformed HTTP/1.1 requests.

5

When was REDHAT-BUG-2447144 published?

REDHAT-BUG-2447144 was published on March 12, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203