CVE-2024-24750
Description
Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.
CWE
- CWE-400 — CWE-400: Uncontrolled Resource Consumption
Affected
- nodejs / undici — v=>= 6.0.0, < 6.6.1 [affected]
CVSS
- 3.1 score=6.5 severity=MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References
- https://github.com/nodejs/undici/security/advisories/GHSA-9f24-jqhm-jfcw x_refsource_CONFIRM
- https://github.com/nodejs/undici/commit/87a48113f1f68f60aa09abb07276d7c35467c663 x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20240419-0006/
Source
cvelistV5-main/cves/2024/24xxx/CVE-2024-24750.json