PatchSiren cyber security CVE debrief
CVE-2026-6734 undici CVE debrief
CVE-2026-6734 is a high-severity vulnerability in the undici library, affecting versions 7.23.0 through 8.1.0. The vulnerability causes cross-origin request routing when using Socks5ProxyAgent, leading to potential credential and data exposure, as well as silent downgrading of HTTPS requests to HTTP. This issue arises because undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. As a result, credentials and request data intended for one origin may be sent to another, and responses from the wrong origin may be trusted. Impacted users are applications that use Socks5ProxyAgent (directly or via setGlobalD
- Vendor
- undici
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-09-10
Who should care
Defenders of applications using undici library, specifically those using Socks5ProxyAgent and making requests to multiple origins, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-6734 is a high-severity vulnerability in undici library, affecting versions 7.23.0 through 8.1.0, causing cross-origin request routing and potential credential and data exposure. Defenders should prioritize upgrading to undici v7.26.0 or v8.2.0, or implementing workarounds.
- Potential credential exposure due to cross-origin request routing
- Potential data exposure due to cross-origin request routing
- Silent downgrading of HTTPS requests to HTTP
- Verification of affected versions and remediation priority
Technical summary
The vulnerability causes cross-origin request routing when using Socks5ProxyAgent, leading to potential credential and data exposure, as well as silent downgrading of HTTPS requests to HTTP. This affects applications that use Socks5ProxyAgent and make requests to more than one origin. The issue is caused by reusing a single connection pool across different origins without verifying the pool's origin matches the requested origin. This results in credentials and request data intended for one origin being sent to another, and responses from the wrong origin being trusted. The vulnerability was introduced in undici 7.23.0 and affects all versions through 8.1.0.
Defensive priority
Defenders should prioritize upgrading to undici v7.26.0 or v8.2.0, or implementing workarounds such as using a separate Socks5ProxyAgent instance per origin.
Recommended defensive actions
- Upgrade to undici v7.26.0 or v8.2.0
- Use a separate Socks5ProxyAgent instance per origin
- Avoid using Socks5ProxyAgent with multiple origins
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The vulnerability was introduced in undici 7.23.0 and affects all versions through 8.1.0. The issue is caused by reusing a single connection pool across different origins without verifying the pool's origin matches the requested origin.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6734 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6734
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6734 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6734
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cna.openjsf.org/security-advisories.html
ce714d77-add3-4f53-aff5-83d477b104bb - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj
ce714d77-add3-4f53-aff5-83d477b104bb - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:22380
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:22934
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:34342
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:35841
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:35891
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:36754
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.