CVE-2026-84961 | undici up to 7.29.0/8.10.1 BalancedPool BalancedPool constructor connect/tls certificate validation

SecurityVulns

A vulnerability marked as problematic has been reported in undici up to 7.29.0/8.10.1. Affected by this issue is the function BalancedPool constructor of the component BalancedPool. Performing a manipulation of the argument connect/tls results in improper certificate validation.

This vulnerability is identified as CVE-2026-84961. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More