CVE-2024-30261

Aliases:GHSA-9qxr-qj54-h672
Modified
Published: 04 Apr 2024, 15:09
Last modified:04 Nov 2025, 16:11

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
3.5 LOW
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability -0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

04 Apr 2024, 15:09
Published
Vulnerability first disclosed
04 Nov 2025, 16:11
Last Modified
Vulnerability information updated

Description

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS Metrics

  • v3.1LOWScore: 2.6CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
  • v3.1LOWScore: 3.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.07% Percentile: 21%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • fedoraprojectfedora

    38 | 39 | 40

  • nodejsundici

    < 5.28.4 | ≥ 6.0.0, < 6.11.1

  • Npmundici

    < 5.28.4 | ≥ 6.0.0, < 6.11.1

References (14)