CVE-2026-18540 | Node.js Undici up to 6.28.0/7.29.1/8.10.2 Retry Interceptor response splitting
A vulnerability was found in Node.js Undici up to 6.28.0/7.29.1/8.10.2. It has been rated as problematic. This vulnerability affects unknown code of the component Retry Interceptor. Performing a manipulation results in http response splitting.
This vulnerability is known as CVE-2026-18540. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More