Repository navigation
chore(deps): update dependency undici to v7 [security] - #154
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
October 5, 2026 15:13
06f0c4f to
b1c9ead
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
October 5, 2026 21:29
b1c9ead to
809cad4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^6.28.0→^7.29.1undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
CVE-2026-84961 / GHSA-w293-vg96-wgc3
More information
Details
Impact
undici's
BalancedPoolpasses its constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstreamPool. JSON cannot represent functions, so a caller-suppliedconnectortlsoption containing acheckServerIdentitycallback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a customcheckServerIdentitywas written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made throughBalancedPool.Client,Pool,Agent, andRoundRobinPooldestructureconnect/tlsbefore the clone and are not affected. Only applications that useBalancedPoolwith a function-valuedconnect/tlsoption (such as a customcheckServerIdentityor connector) are affected.Patches
Upgrade to
7.29.1or8.10.2.BalancedPoolnow preserves theconnectandtlsoptions outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.Workarounds
Use
Client,Pool, orAgentinstead ofBalancedPoolfor connections that rely on a customcheckServerIdentityor connector, until upgraded.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to Denial of Service via orphaned RetryHandler response body
CVE-2026-18149 / GHSA-pmjh-fq2x-6v4x
More information
Details
Impact
undici's
RetryHandlercan leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the originalresponse.bodyheld by the application is never settled, so reads such asresponse.body.text()hang andbodyTimeoutdoes not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.Patches
Patched in undici v7.29.1 and v8.10.2.
Workarounds
Impose an independent request deadline and destroy the response body when it expires.
bodyTimeoutalone does not prevent this.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
CVE-2026-84947 / GHSA-2gqq-gqf2-x968
More information
Details
Impact
undici's
interceptors.dump()reads and discards response bodies up to a configurablemaxSize. When a response declares aContent-Lengththat exceedsmaxSize, the request is aborted cleanly. When a response is sent chunked (noContent-Length) and its body exceedsmaxSize, it is not aborted: the interceptor ends the response early once the accumulated size reachesmaxSize, and continued delivery from the parser triggers an internal assertion that is caught and turned into a request abort and connection tear-down. The application observes a misleading200with an empty or truncated body while the connection is disconnected. Any application using the dump interceptor against untrusted or misbehaving upstreams is affected.Patches
Upgrade to
7.29.1or8.10.2. The dump interceptor now enforcesmaxSizeon both the declared and the received body size, aborting the request with aRequestAbortedErrorinstead of returning a truncated response.Workarounds
None. Avoid using
interceptors.dump()with untrusted upstreams until upgraded.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to downstream response splitting via retry interceptor
CVE-2026-18540 / GHSA-r53p-7pc4-xj5r
More information
Details
Impact
Undici's
interceptors.retry()can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried aContent-Length, the application can receive a longer body. Applications that forward Undici's status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwardedContent-Length, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).For example, a
404 Not FoundwithContent-Length: 2that sends one byte then closes can be resumed with an open-endedRangerequest, and the resumed206 Partial Contentbytes are appended, so the application receives more than two body bytes while still seeingContent-Length: 2. The bug requiresinterceptors.retry()enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculateContent-Length.Patches
Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.
Workarounds
interceptors.retry()for untrusted upstreams, or setmaxRetries: 0.Content-Lengthbefore forwarding a response body assembled by Undici.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
CVE-2026-84933 / GHSA-2jfj-6hjv-fm6j
More information
Details
Impact
undici's
interceptors.cache()does not handleSet-Cookiein the cache path. In shared-cache mode (type: 'shared', the default), a cacheable response (for exampleCache-Control: public, max-age=...) carrying aSet-Cookieheader is stored, and the storedSet-Cookieis re-served to a later caller that hits the same cache key. This exposes one user's cookie to another caller and lets an untrusted upstream inject cookies into cached responses served to all subsequent callers, violating RFC 6265 section 7.2 (a shared cache must not store cookies). Applications using the shared cache interceptor against untrusted or multi-user upstreams are affected. Private caches (type: 'private') are not affected.Patches
Upgrade to
7.29.1or8.10.2. In shared-cache mode, undici no longer stores or re-serves responses containingSet-Cookie, including previously cached entries and revalidation paths.Workarounds
Use a private cache (
type: 'private') for per-user responses, or avoid caching responses that set cookies. Applications acting as shared caches should stripSet-Cookiefrom responses before caching.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to caching and replay of unsafe HTTP method responses
CVE-2026-85008 / GHSA-8436-99hf-9mmv
More information
Details
Impact
undici's
interceptors.cache()documents that it caches only safe HTTP methods. However, its internal skip-list is built by subtracting the configured methods from the safe-methods set, so an unsafe method (POST,PUT,PATCH,DELETE) never lands in the skip-list and is looked up against the cache store. Combined with the storage gate (canCacheResponse) having no method check, a heuristically-cacheable response (for example a404) with an explicitCache-Control: max-age=...to an unsafe method is stored and replayed on a subsequent identical request. The application's state-changing request never reaches the origin, and undici serves a fabricated response from the cache instead. This occurs with the default configuration (methods: ['GET']), which the public API does not allow widening to unsafe methods, so no application misuse is required; an untrusted origin can trigger it purely through its own response headers.Patches
Upgrade to
7.29.1or8.10.2. The cache interceptor no longer reads from or writes to the cache for unsafe HTTP methods, while still invalidating existing cache entries on successful unsafe requests.Workarounds
None.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodejs/undici (undici)
v7.29.1Compare Source
High severity
BalancedPoolcould drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preservesconnectand legacytlsoptions when creating upstreams. Fixed by f690157d.TypeErrorthat could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.Medium severity
WebSocketStreamclose could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.maxSize. Fixed by 2c7d7e12.Low severity
POSTorDELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.Content-Lengthwas present. Undici now enforcesmaxSizeagainst received bytes and aborts oversized responses. Fixed by 21693f40.Content-Rangeagainst the original response framing before resuming. Fixed by cd8af90b.What's Changed
Full Changelog: nodejs/undici@v7.29.0...v7.29.1
v7.29.0Compare Source
High severity
privateCache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 9f10f1e9, with regression coverage in 466e99d1.Medium severity
typeproperty on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generatedcontent-typeheader. Undici now coerces and validates the value before adding it to the request. Fixed by 33928bc2.=in qualifiedno-cacheandprivatedirectives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by 98011a86.Content-Lengthafter resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whoseContent-Lengthis inconsistent withContent-Range. Fixed by 1b5a5312, with corrected fixtures in 4a9dafb1.domainandunparsedvalues passed tosetCookie()could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 3bf91ddb.Full Changelog: nodejs/undici@v7.28.0...v7.29.0
v7.28.0Compare Source
This release line addresses 7 security advisories, all shipped in v7.28.0.
The v7 line is not affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is
an 8.x-only regression.
Summary
8cb10f9804201f893805b8f885a24055d0574cc4d0574cc4ea8930cfHigh severity
WebSocket DoS via fragment count bypass — CVE-2026-12151
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix:
8cb10f98websocket: limit the number of fragments in a message (part of backporta027a4a0Backport WebSocket maxPayloadSize fixes to v7.x, #5423)A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service.
new WebSocket(...)orWebSocketStreamagainst untrusted endpoints.
TLS certificate validation bypass in SOCKS5 ProxyAgent — CVE-2026-9697
GHSA-vmh5-mc38-953g · CWE-295
Fix:
04201f89fix: honor requestTls when proxy is SOCKS5 (#5417)The
ProxyAgentsilently discarded therequestTlsoption when configured witha SOCKS5 proxy. TLS connections through the SOCKS5 tunnel ignored user-configured
parameters such as
ca,cert,key,rejectUnauthorized, andservername,falling back to the default Mozilla CA bundle. Applications relying on
certificate pinning to an internal CA were exposed to man-in-the-middle attacks.
ProxyAgent/Socks5ProxyAgentover SOCKS5 that rely onrequestTls.ProxyAgent, whererequestTlsfunctions correctly.Cross-origin request routing via SOCKS5 proxy pool reuse — CVE-2026-6734
GHSA-hm92-r4w5-c3mj · CWE-346
Fix:
3805b8f8fix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing (#5041)Socks5ProxyAgentreused a single connection pool across different originswithout verifying the pool's origin matched the requested origin. This could
route credentials and request data to unintended destinations, cause responses
from the wrong origin to be trusted, and enable HTTPS→HTTP downgrade.
Socks5ProxyAgentacross multiple origins(introduced in 7.23.0 via #4385).
Moderate severity
Cross-user information disclosure via shared cache whitespace bypass — CVE-2026-9678
GHSA-pr7r-676h-xcf6 · CWE-524
Fix:
85a24055fix(cache): trim qualified field namesThe cache interceptor mishandled responses with whitespace-padded
Cache-Controldirectives such asprivate=" authorization". In shared-cachemode this could cause authenticated data to be cached and served to other users.
Authorizationupstream and receive non-canonical qualified directives.caching authenticated responses, or add
Vary: Authorizationupstream.HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679
GHSA-p88m-4jfj-68fv · CWE-93
Fix:
d0574cc4fix(cookies): preserve values and parse SameSite strictlyparseSetCookieapplied percent-decoding to cookie values, turning encodedsequences like
%0D%0Aand%00into literal bytes, contrary to RFC 6265 §5.4and browser behavior. Applications forwarding parsed Set-Cookie values into
response headers were exposed to header injection, enabling session fixation,
open redirects, and cache poisoning. Introduced in 7.0.0 via
#3789.
NUL,
;, and=.Low severity
Set-Cookie SameSite attribute downgrade — CVE-2026-11525
GHSA-g8m3-5g58-fq7m · CWE-183
Fix:
d0574cc4fix(cookies): preserve values and parse SameSite strictlyThe cookie parser accepted
SameSitevalues containingStrict,Lax, orNoneas substrings rather than requiring exact matches per RFC 6265. Valueslike
SameSite=NoneOfYourBusinessparsed asNone, andSameSite=StrictLaxparsed as
Lax, silently weakening cookie security policies for apps thatforward parsed attributes.
HTTP response queue poisoning via keep-alive socket reuse — CVE-2026-6733
GHSA-35p6-xmwp-9g52 · CWE-367 (TOCTOU race condition)
Fix:
ea8930cffix: guard idle socket validation to skip fresh sockets, hardened by8e4046e4keep idle validation on native timers (#5402) and0fa80869keep idle validation on global timers (#5409)An attacker controlling an upstream HTTP/1.1 server could inject unsolicited
responses onto idle keep-alive sockets. On socket reuse, the injected response
was associated with a new request, delivering responses to the wrong requests.
keep-alive reuse.
keepAliveTimeout: 0on theClient or Pool.
Release contents & deliberate backports
v7.28.0 is a security-only release — every change in it is one of the fixes
above, backported to the v7.x maintenance line on purpose from the v8
development line:
#5423— backport of the WebSocketmaxPayloadSizefragment-count / cumulative-size limits (CVE-2026-12151).#5402ᔡ— backport of the idle-validation hardening (native + global timers) for the queue-poisoning fix (CVE-2026-6733).#5417—requestTlsover SOCKS5 fix (CVE-2026-9697).The cookie (
d0574cc4),cache (
85a24055) andqueue-poisoning core (
ea8930cf)fixes were applied directly to the v7.x branch. Full changelog:
v7.27.2...v7.28.0.Credits
Per-advisory credits (as recorded in each GHSA):
v7.27.2Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.27.1...v7.27.2
v7.27.1Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.27.0...v7.27.1
v7.27.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.26.0...v7.27.0
v7.26.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.25.0...v7.26.0
v7.25.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.8...v7.25.0
v7.24.8Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.7...v7.24.8
v7.24.7Compare Source
What's Changed
redirectionLimitReachedby @samuel871211 in #4933New Contributors
Full Changelog: nodejs/undici@v7.24.6...v7.24.7
v7.24.6Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.24.5...v7.24.6
v7.24.5Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.24.4...v7.24.5
v7.24.4Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.3...v7.24.4
v7.24.3Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.2...v7.24.3
v7.24.2Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.1...v7.24.2
v7.24.1Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.0...v7.24.1
v7.24.0Compare Source
Undici v7.24.0 Security Release Notes
This release addresses multiple security vulnerabilities in Undici.
Upgrade guidance
All users on v7 should upgrade to v7.24.0 or later.
Fixed advisories
GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 (Medium)
Inconsistent interpretation of HTTP requests (request/response smuggling class issue).
GHSA-f269-vfmq-vjvj / CVE-2026-1528 (High)
Malicious WebSocket 64-bit frame length handling could crash the client.
GHSA-phc3-fgpg-7m6h / CVE-2026-2581 (Medium)
Unbounded memory consumption in deduplication interceptor response buffering (DoS risk).
GHSA-4992-7rv2-5pvq / CVE-2026-1527 (Medium)
CRLF injection via the
upgradeoption.GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 (High)
Unhandled exception from invalid
server_max_window_bitsin WebSocket permessage-deflate negotiation.GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 (High)
Unbounded memory consumption in WebSocket permessage-deflate decompression.
Affected and patched ranges
7.0.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.0>= 7.17.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.0References
v7.23.0Compare Source
What's Changed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.