CVE-2024-24750: Node.js Undici
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.
Affected products
- Node.js Undici: from 6.0.0, before 6.6.1 (fixed in 6.6.1)
Published 2024-02-16. Last modified 2026-06-17.