Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
undici Vendor: nodejs

About This Product

undici is a software product offered by nodejs. This product is widely deployed in production environments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The moderate vulnerability count reflects ongoing security research and responsible disclosure practices. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 43 known vulnerabilities affecting nodejs undici. This includes 12 high-severity issues requiring prompt remediation. Vulnerabilities in this product have been disclosed spanning from 2022 to 2026, indicating a recent active security attention. 21 medium-severity issues and 10 low-severity issues complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2022-32210 2022-07-14 2026-06-17 6.5 - -
CVE-2022-31150 2022-07-19 2026-06-17 5.3 - -
CVE-2022-31151 2022-07-21 2026-06-17 3.7 - -
CVE-2022-35949 2022-08-12 2026-06-17 5.3 - -
CVE-2022-35948 2022-08-15 2026-06-17 5.3 - -
CVE-2023-23936 2023-02-16 2026-06-17 6.5 - -
CVE-2023-24807 2023-02-16 2026-06-17 7.5 - -
CVE-2023-45143 2023-10-12 2026-06-17 3.9 - -
CVE-2024-24750 2024-02-16 2026-06-17 6.5 - -
CVE-2024-24758 2024-02-16 2026-06-17 3.9 - -
CVE-2024-30261 2024-04-04 2026-06-17 2.6 - -
CVE-2024-30260 2024-04-04 2026-06-17 3.9 - -
CVE-2026-22036 2026-01-14 2026-06-17 5.9 - -
CVE-2026-1525 2026-03-12 2026-06-17 6.5 - -
CVE-2026-1526 2026-03-12 2026-09-04 7.5 - -
CVE-2026-1527 2026-03-12 2026-06-17 4.6 - -
CVE-2026-1528 2026-03-12 2026-09-04 7.5 - -
CVE-2026-2229 2026-03-12 2026-09-04 7.5 - -
CVE-2026-2581 2026-03-12 2026-06-17 5.9 - -
CVE-2026-12151 2026-06-17 2026-09-11 7.5 - -
CVE-2026-9675 2026-06-17 2026-06-25 7.5 - -
CVE-2026-11525 2026-06-17 2026-06-25 3.7 - -
CVE-2026-6733 2026-06-17 2026-06-27 3.7 - -
CVE-2026-6734 2026-06-17 2026-09-10 7.5 - -
CVE-2026-9678 2026-06-17 2026-06-25 5.9 - -
CVE-2026-9679 2026-06-17 2026-06-25 5.9 - -
CVE-2026-9697 2026-06-17 2026-09-10 7.4 - -
CVE-2026-13697 2026-07-29 2026-08-04 7.4 - -
CVE-2026-16729 2026-07-29 2026-08-05 4.8 - -
CVE-2026-16728 2026-07-29 2026-08-04 4.8 - -
CVE-2026-14643 2026-07-29 2026-08-04 5.9 - -
CVE-2026-15157 2026-07-29 2026-08-04 4.2 - -
CVE-2026-84933 2026-09-04 2026-09-15 6.5 - -
CVE-2026-84947 2026-09-04 2026-09-15 3.7 - -
CVE-2026-84961 2026-09-04 2026-09-15 7.4 - -
CVE-2026-85008 2026-09-04 2026-09-15 3.7 - -
CVE-2026-85014 2026-09-04 2026-09-15 5.9 - -
CVE-2026-85024 2026-09-04 2026-09-16 5.9 - -
CVE-2026-85152 2026-09-04 2026-09-16 7.4 - -
CVE-2026-18149 2026-09-04 2026-09-16 5.9 - -
CVE-2026-18540 2026-09-04 2026-09-16 3.7 - -
CVE-2026-19534 2026-09-04 2026-09-16 7.5 - -
CVE-2026-84890 2026-09-04 2026-09-11 5.9 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for nodejs undici by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.