GHSA-pgw7-wx7w-2w33

    Dashboard / Vulnerabilities / GHSA-pgw7-wx7w-2w33

    GHSA-pgw7-wx7w-2w33

    Published: 17 Jun 2022Last Modified: 8 Jul 2026

    Summary: ProxyAgent vulnerable to MITM

    Details: ### Description `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server. ### Impact This affects all use of HTTPS via HTTP proxy using **`Undici.ProxyAgent`** with Undici or Node's global `fetch`. In this case, it removes all HTTPS security from all requests sent using Undici's `ProxyAgent`, allowing trivial MitM attacks by anybody on the network path between the client and the target server (local network users, your ISP, the proxy, the target server's ISP, etc). This less seriously affects HTTPS via HTTPS proxies. When you send HTTPS via a proxy to a remote server, the proxy can freely view or modify all HTTPS traffic unexpectedly (but only the proxy). ### Patches This issue was patched in Undici v5.5.1. ### Workarounds At the time of writing, the only workaround is to not use `ProxyAgent` as a dispatcher for TLS Connections.

    Affected packages

    Package

    Name: undici

    Purl: pkg:npm/undici

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.8.2
    Fixed -5.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-pgw7-wx7w-2w33 | CVE-DB