External risk intelligence

Undici BalancedPool Discards TLS Options Leading to Improper Certificate Validation.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-84961

The vulnerability affects Undici's BalancedPool when developers supply function-valued TLS options, which are discarded during internal deep-cloning. Exploitation depends on the application using this specific pool configuration and having a custom checkServerIdentity or connector. Reachability is therefore determined by specific developer implementation rather than inherent library exposure.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a security vulnerability in the undici library used within Node.js. The issue arises when a specific component, BalancedPool, processes custom security options, potentially leading to the acceptance of unauthorized connections. While the vulnerability exists, its exploitation is dependent on specific implementation choices by developers.

  • Custom security settings may be ignored.
  • Affects how applications verify server identities.
  • Confirm relevance and exposure within your Node.js use.

Attack Path

How an attacker could exploit the issue

An attacker can leverage this vulnerability by sending a request to an application that uses the vulnerable `BalancedPool` constructor within the `undici` library. If the application improperly configures `BalancedPool` with function-valued TLS options, these functions are discarded during JSON serialization. This allows an attacker to bypass custom server identity checks, potentially leading to Man-in-the-Middle attacks.

  • No special access required for the attacker.
  • Triggered by specific `BalancedPool` configuration.
  • Allows bypassing server identity checks.

Live Threat

Current exploitation, exposure, and threat context

When the `undici` library's `BalancedPool` constructor is used with custom TLS options, such as a `checkServerIdentity` callback or a custom `connect` option, these functions are silently dropped due to JSON serialization. This could allow a peer with a certificate that should be rejected by the custom logic to be accepted if it passes Node.js's default checks, potentially leading to man-in-the-middle attacks when these specific, unsupported configurations are in use.

  • Invalid TLS certificates could be accepted.
  • Custom TLS validation logic may be bypassed.
  • Application trust in network connections is undermined.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this vulnerability, application owners and platform teams should collaborate to identify instances of the affected Undici library within their Node.js deployments. The immediate priority is to confirm whether the vulnerable `BalancedPool` configuration, specifically with function-valued TLS options, is in use and if these instances are exposed externally or handle sensitive data. Once identified and prioritized by risk, a plan for upgrading the Undici library should be executed, potentially requiring coordination with development teams and scheduling during maintenance windows.

  • Application owners and platform teams must own remediation.
  • Verify usage of `BalancedPool` with function-valued TLS options.
  • Upgrade to supported versions of Undici.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the undici library?

Undici is an HTTP client library for Node.js, built to provide a high-performance alternative to the built-in HTTP module. It is frequently used in Node.js applications to manage connections and handle network requests. The vulnerable BalancedPool component is a specific feature within undici used to distribute requests across multiple connections, helping applications maintain performance under load.

What is the CWE-295 weakness in CVE-2026-84961?

CVE-2026-84961 involves Improper Certificate Validation, categorized as CWE-295. In this case, the BalancedPool component inadvertently discards security-critical functions, such as custom callbacks meant to verify server identities, because it uses a JSON-based cloning process that cannot handle function objects. This effectively silences your custom security logic, leaving the application to rely only on basic default checks.

How is this vulnerability triggered?

The flaw is triggered only when a developer explicitly configures BalancedPool with a function-valued option, such as a custom checkServerIdentity callback. If you are using the standard Pool, Client, or Agent dispatchers, you are not affected. Furthermore, if you are not using custom logic to override the default TLS certificate validation process, the discarded options will not result in a loss of security.

Do I need to worry if my service is internal?

According to Halo Surface Signal, the risk depends heavily on your specific code configuration rather than just network reachability. While external-facing services naturally carry higher risk for any authentication bypass, this vulnerability requires an attacker to intercept your specific network traffic. You should prioritize internal services that handle sensitive data or communicate with untrusted downstream systems.

How do I remediate this issue?

Start by auditing your codebase to locate any use of the BalancedPool constructor. Check if you are passing function-valued TLS or connection options. If you find such configurations, upgrade to undici version 7.29.1 or 8.10.2 immediately. These versions contain the necessary logic to preserve your custom security callbacks, ensuring they are not lost during object processing.

References