What is CVE-2026-15157?
CVE-2026-15157: The undici library fails to validate the `type` property of a duck-typed blob-like request body before using it as the Content-Type header in the HTTP/1.1 dispatcher. This affects versions prior to 6.28.0, 7.29.0, and 8.9.0; users should update to the latest version to prevent potential header injection.
Azərbaycanca: CVE-2026-15157: undici kitabxanası duck-typed blob tipli sorğu gövdəsində `type` xassəsini düzgün yoxlamır və onu birbaşa HTTP/1.1 dispatcher üçün Content-Type başlığı kimi istifadə edir. Bu, 6.28.0, 7.29.0 və 8.9.0-dən əvvəlki versiyalara təsir edir; tətbiq sahibləri kitabxananı ən son versiyaya yeniləməlidir.
FAQ2
Which versions of undici are affected by CVE-2026-15157?
This vulnerability affects undici library versions prior to 6.28.0, 7.29.0, and 8.9.0.
How can one mitigate CVE-2026-15157?
Users should update the undici library to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.