Site icon API Security Blog

CRLF Injection

Undici is is vulnerable to CRLF injection. The vulnerability is due to improper request header `content-type` sanitization in `lib/core/request.js`. An attacker can exploit this vulnerability to preform two requests in a single API call.Read More

Exit mobile version