undici ProxyAgent TLS drop (SOCKS5, v7.23.08.4.x)
CVE-2026-9697 Published on June 17, 2026
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
Impact:
undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.
Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.
Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.
Patches:
Upgrade to undici v7.28.0 or v8.5.0.
Workarounds:
No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.
Vulnerability Analysis
CVE-2026-9697 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-9697
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
undici:- Version 7.23.0 and below 7.28.0 is affected.
- Version 7.28.0 is unaffected.
- Version 8.0.0 and below 8.5.0 is affected.
- Version 8.5.0 is unaffected.
- Version 4.2.0-13 and below * is unaffected.
- Version 1:24.18.0-1.el10_2 and below * is unaffected.
- Version 8100020260630152626.6d880403 and below * is unaffected.
- Version 9080020260626074955.rhel9 and below * is unaffected.
- Version 1782840519 and below * is unaffected.
- Version 1782839981 and below * is unaffected.
- Version 1782839193 and below * is unaffected.
- Version 1782838753 and below * is unaffected.
- Version 1782841925 and below * is unaffected.
- Version 1782844225 and below * is unaffected.
- Version 1782839658 and below * is unaffected.
- Version 1782838476 and below * is unaffected.
- Version 1782839494 and below * is unaffected.
- Version 1783448184 and below * is unaffected.
- Version 1784210921 and below * is unaffected.
- Version 26.3.0-1.2.hum1 and below * is unaffected.
- Version 1.96.0-1.hum1 and below * is unaffected.
- Version 24.18.0-0.3.hum1 and below * is unaffected.
- Version 25.9.0-1.1.hum1 and below * is unaffected.
- Version 1787121387 and below * is unaffected.
- Version 1783306396 and below * is unaffected.
- Version 1784744859 and below * is unaffected.
- Version 1786705347 and below * is unaffected.
- Version 1786706101 and below * is unaffected.
- Version 1786705558 and below * is unaffected.
- Version 1786705646 and below * is unaffected.
- Version 1786706138 and below * is unaffected.
- Version 1786705741 and below * is unaffected.
- Version 1786705777 and below * is unaffected.
- Version 1786705802 and below * is unaffected.
- Version 1786705938 and below * is unaffected.
- Version 1786706577 and below * is unaffected.
- Version 1786706125 and below * is unaffected.
- Version 1786706177 and below * is unaffected.
- Version 1786706188 and below * is unaffected.
- Version 1786706679 and below * is unaffected.
- Version 1786706357 and below * is unaffected.
- Version 1786706612 and below * is unaffected.
- Version 1786706644 and below * is unaffected.
- Version 1786706659 and below * is unaffected.
- Version 1786706880 and below * is unaffected.
- Version 1786701839 and below * is unaffected.
- Version 1786701555 and below * is unaffected.
- Version 1786702052 and below * is unaffected.
- Version 1786702559 and below * is unaffected.
- Version 1786702713 and below * is unaffected.
- Version 1786702264 and below * is unaffected.
- Version 1786702448 and below * is unaffected.
- Version 1786702276 and below * is unaffected.
- Version 1786702440 and below * is unaffected.
- Version 1786702315 and below * is unaffected.
- Version 1786703071 and below * is unaffected.
- Version 1786702563 and below * is unaffected.
- Version 1786702636 and below * is unaffected.
- Version 1786702623 and below * is unaffected.
- Version 1786703137 and below * is unaffected.
- Version 1786702716 and below * is unaffected.
- Version 1786702872 and below * is unaffected.
- Version 1786702949 and below * is unaffected.
- Version 1786702917 and below * is unaffected.
- Version 1786703143 and below * is unaffected.
- Version 1786627460 and below * is unaffected.
- Version 1786626399 and below * is unaffected.
- Version 1786628235 and below * is unaffected.
- Version 1786627106 and below * is unaffected.
- Version 1786629761 and below * is unaffected.
- Version 1786627559 and below * is unaffected.
- Version 1786687918 and below * is unaffected.
- Version 1786629478 and below * is unaffected.
- Version 1786628142 and below * is unaffected.
- Version 1786631508 and below * is unaffected.
- Version 1786628053 and below * is unaffected.
- Version 1786627382 and below * is unaffected.
- Version 1786627430 and below * is unaffected.
- Version 1786629076 and below * is unaffected.
- Version 1786627469 and below * is unaffected.
- Version 1786644072 and below * is unaffected.
- Version 1786688215 and below * is unaffected.
- Version 1786628340 and below * is unaffected.
- Version 1786628623 and below * is unaffected.
- Version 1786632256 and below * is unaffected.
- Version 1786628935 and below * is unaffected.
- Version 1786629548 and below * is unaffected.
- Version 1782498792 and below * is unaffected.
- Version 1783007534 and below * is unaffected.
- Version 1782989367 and below * is unaffected.
- Version 1785245777 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.