CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-15157

mediumCVSS 4.2covered by 3 sourcesfirst seen 2026-07-29
Impact When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via request(), stream(), pipeline(), or dispatch()) with a .type derived from untrusted input, an attacker can inject CRLF sequences (\r\n) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream. The vulnerable branch in lib/dispatcher/client-h1.js pushes body.type directly into the outgoing headers with no validation, while every other header path in undici goes through isValidHeaderValue(): } else if (util.isBlobLike(body) && request.contentType == null && body.type) { headers.push('content-type', body.type) // bypasses isValidHeaderValue() } The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled .type. Native Blob is safe because its constructor strips CRLF from .type. fetch() is unaffected because it validates via the Headers class. Ecosystem consumers that build duck-typed blob shapes from user input include form-data-encoder, formdata-polyfill, and formdata-node. Same defect class as CVE-2022-35948 (explicit content-type sink, fixed in undici 5.8.2) and CVE-2026-1527 (upgrade option sink, fixed in 6.24.0 / 7.24.0), both closed by adding isValidHeaderValue() on their respective sinks. This branch was missed. Patches Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later. Workarounds - Set an explicit, validated content-type header on the request options (skips the vulnerable branch). - Use a native Blob (or fetch-blob) instead of a hand-rolled duck-typed object. - Reject control characters in the MIME type before assigning it to .type. - Use fetch() instead of the non-fetch APIs.

CSIRTS triage

What
CRLF injection vulnerability in handling of blob-like body 'type' property allows injection of carriage return and line feed characters.
Who is affected
Applications using undici HTTP client library with untrusted blob-like request bodies.
Urgency
Medium priority; not yet exploited in the wild but CRLF injection can enable protocol confusion attacks.
Action
Update undici to patched version when available.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-15157

Get an email if CVE-2026-15157 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-15157

CVE.org record

Embed the live status

CVE-2026-15157 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-15157 status](https://www.csirts.com/badge/CVE-2026-15157)](https://www.csirts.com/cve/CVE-2026-15157)