Back to Database
Status published
Low
CVE-2024-30260
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Vulnerability Description
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-30260
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7
- https://github.com/nodejs/undici/commit/64e3402da4e032e68de46acb52800c9a06aaea3f
- https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ/
More from nodejs
View All →CVE-2025-59466
We have identified a bug in Node.js error handling where...
Medium
5.9
CVE-2025-59465
A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data...
High
7.5
CVE-2025-59464
A memory leak in Node.js’s OpenSSL integration occurs when converting...
Medium
6.5
CVE-2025-55132
A flaw in Node.js's permission model allows a file's access...
Low
2.8
CVE-2025-55131
A flaw in Node.js's buffer allocation logic can expose uninitialized...
High
7.1
Affected Vendor
nodejs
View all reports →Affected Software
undici
Vulnerable Versions:
< 5.28.4, >= 6.0.0, < 6.11.1
Timeline
Official Publish:
April 4th, 2024
Last Modified:
November 4th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L