CVE-2024-24750

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 16, 2024
Updated: Dec 17, 2024
CWE ID 400
CWE ID 401

Summary

CVE-2024-24750 is a memory leak vulnerability affecting Undici, an HTTP/1.1 client for Node.js. In vulnerable versions, if `fetch(url)` is called without consuming the incoming body or consuming it too slowly, memory leaks occur. Users are strongly advised to upgrade to version 6.6.1 to address this issue. For those unable to upgrade, it's crucial to always consume the incoming body to prevent memory leaks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share