More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2366632 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
This issue was fixed in undici-version 6.21.2 (https://github.com/advisories/GHSA-cxrh-j4jr-qwg3), which was used in nodejs2w version 22.15.0 (https://nodejs.org/en/blog/release/v22.15.0). Current version in fedora is 22.20.0, therefore closing the bug.