undici ProxyAgent TLS drop (SOCKS5, v7.23.08.4.x)
CVE-2026-9697 Published on June 17, 2026
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
Impact:
undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.
Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange.
Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added.
Patches:
Upgrade to undici v7.28.0 or v8.5.0.
Workarounds:
No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.
Vulnerability Analysis
CVE-2026-9697 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-9697
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
undici:- Version 7.23.0 and below 7.28.0 is affected.
- Version 7.28.0 is unaffected.
- Version 8.0.0 and below 8.5.0 is affected.
- Version 8.5.0 is unaffected.
- Version 1:24.18.0-1.el10_2 and below * is unaffected.
- Version 8100020260630152626.6d880403 and below * is unaffected.
- Version 9080020260626074955.rhel9 and below * is unaffected.
- Version 1782840519 and below * is unaffected.
- Version 1782839981 and below * is unaffected.
- Version 1782839193 and below * is unaffected.
- Version 1782838753 and below * is unaffected.
- Version 1782841925 and below * is unaffected.
- Version 1782844225 and below * is unaffected.
- Version 1782839658 and below * is unaffected.
- Version 1782838476 and below * is unaffected.
- Version 1782839494 and below * is unaffected.
- Version 1783448184 and below * is unaffected.
- Version 26.3.0-1.2.hum1 and below * is unaffected.
- Version 1.96.0-1.hum1 and below * is unaffected.
- Version 24.18.0-0.3.hum1 and below * is unaffected.
- Version 25.9.0-1.1.hum1 and below * is unaffected.
- Version 1783306396 and below * is unaffected.
- Version 1782498792 and below * is unaffected.
- Version 1783007534 and below * is unaffected.
- Version 1782989367 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.