CVE-2026-1527 | undici 1.js HTTP Service client-h1.js crlf injection (EUVD-2026-11701)
A vulnerability was found in undici 1.js and classified as problematic. The affected element is an unknown function in the library lib/dispatcher/client-h1.js of the component HTTP Service. Such manipulation leads to crlf injection.
This vulnerability is traded as CVE-2026-1527. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.