CVE-2026-22036: Node.js Undici
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation. This vulnerability is fixed in 7.18.0 and 6.23.0.
Affected products
- Node.js Undici: before 6.23.0 (fixed in 6.23.0); from 7.0.0, before 7.18.2 (fixed in 7.18.2)
Published 2026-01-14. Last modified 2026-06-17.