CVE-2023-23936: Node.js

Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.

Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.

Affected products

  • Node.js Node.js: from 16.0.0, before 16.19.1 (fixed in 16.19.1); from 18.0.0, before 18.14.1 (fixed in 18.14.1); from 19.0.0, before 19.6.1 (fixed in 19.6.1)
  • Node.js Undici: from 2.0.0, before 5.19.1 (fixed in 5.19.1)

Published 2023-02-16. Last modified 2026-06-17.