PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6734 undici CVE debrief

CVE-2026-6734 is a high-severity vulnerability in the undici library, affecting versions 7.23.0 through 8.1.0. The vulnerability causes cross-origin request routing when using Socks5ProxyAgent, leading to potential credential and data exposure, as well as silent downgrading of HTTPS requests to HTTP. This issue arises because undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. As a result, credentials and request data intended for one origin may be sent to another, and responses from the wrong origin may be trusted. Impacted users are applications that use Socks5ProxyAgent (directly or via setGlobalD

Vendor
undici
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-09-10
Advisory published
2026-06-17
Advisory updated
2026-09-10

Who should care

Defenders of applications using undici library, specifically those using Socks5ProxyAgent and making requests to multiple origins, should assess exposure and prioritize remediation.

Why it matters

CVE-2026-6734 is a high-severity vulnerability in undici library, affecting versions 7.23.0 through 8.1.0, causing cross-origin request routing and potential credential and data exposure. Defenders should prioritize upgrading to undici v7.26.0 or v8.2.0, or implementing workarounds.

  • Potential credential exposure due to cross-origin request routing
  • Potential data exposure due to cross-origin request routing
  • Silent downgrading of HTTPS requests to HTTP
  • Verification of affected versions and remediation priority

Technical summary

The vulnerability causes cross-origin request routing when using Socks5ProxyAgent, leading to potential credential and data exposure, as well as silent downgrading of HTTPS requests to HTTP. This affects applications that use Socks5ProxyAgent and make requests to more than one origin. The issue is caused by reusing a single connection pool across different origins without verifying the pool's origin matches the requested origin. This results in credentials and request data intended for one origin being sent to another, and responses from the wrong origin being trusted. The vulnerability was introduced in undici 7.23.0 and affects all versions through 8.1.0.

Defensive priority

Defenders should prioritize upgrading to undici v7.26.0 or v8.2.0, or implementing workarounds such as using a separate Socks5ProxyAgent instance per origin.

Recommended defensive actions

  • Upgrade to undici v7.26.0 or v8.2.0
  • Use a separate Socks5ProxyAgent instance per origin
  • Avoid using Socks5ProxyAgent with multiple origins
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The vulnerability was introduced in undici 7.23.0 and affects all versions through 8.1.0. The issue is caused by reusing a single connection pool across different origins without verifying the pool's origin matches the requested origin.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6734 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6734

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6734 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6734

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://cna.openjsf.org/security-advisories.html

    ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj

    ce714d77-add3-4f53-aff5-83d477b104bb - Mitigation, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:22380

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:22934

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:34342

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:35841

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:35891

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:36754

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.