CVE-2026-15157
Impact
When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via request(), stream(), pipeline(), or dispatch()) with a .type derived from untrusted input, an attacker can inject CRLF sequences (\r\n) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.
The vulnerable branch in lib/dispatcher/client-h1.js pushes body.type directly into the outgoing headers with no validation, while every other header path in undici goes through isValidHeaderValue():
} else if (util.isBlobLike(body) && request.contentType == null && body.type) {
headers.push('content-type', body.type) // bypasses isValidHeaderValue()
}
The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled .type. Native Blob is safe because its constructor strips CRLF from .type. fetch() is unaffected because it validates via the Headers class. Ecosystem consumers that build duck-typed blob shapes from user input include form-data-encoder, formdata-polyfill, and formdata-node.
Same defect class as CVE-2022-35948 (explicit content-type sink, fixed in undici 5.8.2) and CVE-2026-1527 (upgrade option sink, fixed in 6.24.0 / 7.24.0), both closed by adding isValidHeaderValue() on their respective sinks. This branch was missed.
Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.
Workarounds
- Set an explicit, validated content-type header on the request options (skips the vulnerable branch).
- Use a native Blob (or fetch-blob) instead of a hand-rolled duck-typed object.
- Reject control characters in the MIME type before assigning it to .type.
- Use fetch() instead of the non-fetch APIs.
CSIRTS triage
- What
- CRLF injection vulnerability in handling of blob-like body 'type' property allows injection of carriage return and line feed characters.
- Who is affected
- Applications using undici HTTP client library with untrusted blob-like request bodies.
- Urgency
- Medium priority; not yet exploited in the wild but CRLF injection can enable protocol confusion attacks.
- Action
- Update undici to patched version when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-15157
Get an email if CVE-2026-15157 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
Advisory coverage (3)
- mediumCVE-2026-15157: undici vulnerable to CRLF Injection via blob-like body 'type' propertymsrc · 2026-08-06
- mediumGHSA-m8rv-5g2x-5cg5: undici vulnerable to CRLF Injection via blob-like body 'type' propertyghsa · 2026-08-03
- mediumCVE-2026-15157: undici does not validate the type property of a duck-typed blob-like request body before using…nvd · 2026-07-29
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-15157)