CVE-2024-30261

All FrameworksNode.jsCWE-284CVE-2024-30261

CVE-2024-30261

State: PUBLISHED · Published: 2024-04-04 · Updated: 2025-11-04 · Assigner: GitHub_M
Description
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2024/30xxx/CVE-2024-30261.json