CVE-2022-32210
JavaScript vulnerability analysis and mitigation

Overview

CVE-2022-32210 affects Undici's ProxyAgent functionality, discovered and disclosed in June 2022. The vulnerability impacts versions from 4.8.2 up to (excluding) 5.5.1 of the Undici HTTP/1.1 client for Node.js. This security flaw involves improper certificate validation in the ProxyAgent component (GitHub Advisory).

Technical details

The vulnerability stems from Undici.ProxyAgent's failure to verify remote server certificates and its exposure of all request and response data to the proxy. The issue has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N. It is classified under CWE-295 (Improper Certificate Validation) (NVD).

Impact

The vulnerability allows proxies to perform Man-in-the-Middle (MITM) attacks on all HTTPS traffic. When using HTTP proxies, HTTPS requests are transmitted in plain text between Undici and the proxy server, effectively removing all HTTPS security. This enables potential MITM attacks by any entity on the network path between the client and target server, including local network users, ISPs, and the proxy itself (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in Undici version 5.5.1. Prior to the patch, the only workaround was to avoid using ProxyAgent as a dispatcher for TLS Connections (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.5
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH7.5
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2026-22028HIGH7.2
  • JavaScriptJavaScript
  • preact
NoYesJan 07, 2026
CVE-2025-9611HIGH7.2
  • JavaScriptJavaScript
  • @playwright/mcp
NoYesJan 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management