fix(deps): update dependency undici@<6.23.0 to >=8.10.2 [security] - #1157
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Thank you for following the naming conventions! 🙏 |
2f51146 to
39857cc
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
39857cc to
888da45
Compare
|
Superseded by the consolidated dependency update now on |
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This PR contains the following updates:
>=8.10.0→>=8.10.2undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression
CVE-2026-85024 / GHSA-3wwx-pv8p-q78v
More information
Details
Impact
undici's WebSocket client (including Node.js's bundled
globalThis.WebSocket) crashes the entire Node.js process when a remote WebSocket peer sends a permessage-deflate compressed message that crosses the decompressed-payload size limit and then contains a malformed DEFLATE block. Inlib/web/websocket/permessage-deflate.js, the size-limit cleanup callsremoveAllListeners()on the internal zlibInflateRaw, removing itserrorlistener, but leaves the stream running. The inflater then emits aZ_DATA_ERRORwith no listener attached, which Node.js treats as a fatal unhandlederrorevent and terminates the process. Applicationerror/closehandlers on the public WebSocket cannot observe or prevent this, because the failing object is the internalInflateRaw.A malicious or compromised WebSocket server can crash a client with a single connection, unauthenticated and without any application mistake. The attack is asymmetric (about 130 KB on the wire expands past the limit) and can be repeated on reconnect (crash loop).
Affected applications are those using the undici WebSocket client (
new WebSocket(...)) or Node.js's bundledglobalThis.WebSocketthat can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.Patches
Upgrade to undici v6.28.1, v7.29.1 or v8.10.2.
Workarounds
No workaround is available.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
CVE-2026-85152 / GHSA-vp8m-p9jh-q5pm
More information
Details
Impact
When
interceptors.cache()orinterceptors.deduplicate()is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its ownorigin, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.An attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.
Applications that share
interceptors.cache()orinterceptors.deduplicate()state across origins are affected. AnAgentis not affected, because its dispatch options include the request origin.This was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.
Patches
Upgrade to undici v8.10.2.
Workarounds
Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to Denial of Service via WebSocketStream unclean close
CVE-2026-85014 / GHSA-rx4f-c7p8-82vq
More information
Details
Impact
undici's
WebSocketStreamcrashes the client process when a WebSocket connection is closed abruptly without a close handshake. On such an unclean close, the internal socket-close handler callsabort()on the writable stream even when the application holds a writer lock. Per the WHATWG Streams standard, aborting a locked stream returns a promise that rejects with aTypeError, and the handler discards that promise. The unobserved rejection surfaces as anunhandledRejectionand, under Node.js's default behavior, terminates the process.A malicious or compromised WebSocket server can crash a client with a single connection teardown (a TCP reset, a proxy teardown, or a protocol-violating frame). Affected applications are those using the
WebSocketStreamAPI and writing through a writer, which is the standard way to write.All releases from undici 7.0.0 are affected. WebSocketStream was introduced in 7.0.0.
Patches
Upgrade to undici v7.29.1 or v8.10.2.
Workarounds
No workaround is available.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to caching and replay of unsafe HTTP method responses
CVE-2026-85008 / GHSA-8436-99hf-9mmv
More information
Details
Impact
undici's
interceptors.cache()documents that it caches only safe HTTP methods. However, its internal skip-list is built by subtracting the configured methods from the safe-methods set, so an unsafe method (POST,PUT,PATCH,DELETE) never lands in the skip-list and is looked up against the cache store. Combined with the storage gate (canCacheResponse) having no method check, a heuristically-cacheable response (for example a404) with an explicitCache-Control: max-age=...to an unsafe method is stored and replayed on a subsequent identical request. The application's state-changing request never reaches the origin, and undici serves a fabricated response from the cache instead. This occurs with the default configuration (methods: ['GET']), which the public API does not allow widening to unsafe methods, so no application misuse is required; an untrusted origin can trigger it purely through its own response headers.Patches
Upgrade to
7.29.1or8.10.2. The cache interceptor no longer reads from or writes to the cache for unsafe HTTP methods, while still invalidating existing cache entries on successful unsafe requests.Workarounds
None.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
CVE-2026-84961 / GHSA-w293-vg96-wgc3
More information
Details
Impact
undici's
BalancedPoolpasses its constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstreamPool. JSON cannot represent functions, so a caller-suppliedconnectortlsoption containing acheckServerIdentitycallback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a customcheckServerIdentitywas written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made throughBalancedPool.Client,Pool,Agent, andRoundRobinPooldestructureconnect/tlsbefore the clone and are not affected. Only applications that useBalancedPoolwith a function-valuedconnect/tlsoption (such as a customcheckServerIdentityor connector) are affected.Patches
Upgrade to
7.29.1or8.10.2.BalancedPoolnow preserves theconnectandtlsoptions outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.Workarounds
Use
Client,Pool, orAgentinstead ofBalancedPoolfor connections that rely on a customcheckServerIdentityor connector, until upgraded.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
CVE-2026-84947 / GHSA-2gqq-gqf2-x968
More information
Details
Impact
undici's
interceptors.dump()reads and discards response bodies up to a configurablemaxSize. When a response declares aContent-Lengththat exceedsmaxSize, the request is aborted cleanly. When a response is sent chunked (noContent-Length) and its body exceedsmaxSize, it is not aborted: the interceptor ends the response early once the accumulated size reachesmaxSize, and continued delivery from the parser triggers an internal assertion that is caught and turned into a request abort and connection tear-down. The application observes a misleading200with an empty or truncated body while the connection is disconnected. Any application using the dump interceptor against untrusted or misbehaving upstreams is affected.Patches
Upgrade to
7.29.1or8.10.2. The dump interceptor now enforcesmaxSizeon both the declared and the received body size, aborting the request with aRequestAbortedErrorinstead of returning a truncated response.Workarounds
None. Avoid using
interceptors.dump()with untrusted upstreams until upgraded.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
CVE-2026-84933 / GHSA-2jfj-6hjv-fm6j
More information
Details
Impact
undici's
interceptors.cache()does not handleSet-Cookiein the cache path. In shared-cache mode (type: 'shared', the default), a cacheable response (for exampleCache-Control: public, max-age=...) carrying aSet-Cookieheader is stored, and the storedSet-Cookieis re-served to a later caller that hits the same cache key. This exposes one user's cookie to another caller and lets an untrusted upstream inject cookies into cached responses served to all subsequent callers, violating RFC 6265 section 7.2 (a shared cache must not store cookies). Applications using the shared cache interceptor against untrusted or multi-user upstreams are affected. Private caches (type: 'private') are not affected.Patches
Upgrade to
7.29.1or8.10.2. In shared-cache mode, undici no longer stores or re-serves responses containingSet-Cookie, including previously cached entries and revalidation paths.Workarounds
Use a private cache (
type: 'private') for per-user responses, or avoid caching responses that set cookies. Applications acting as shared caches should stripSet-Cookiefrom responses before caching.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to Denial of Service via unbounded decompression of compressed responses
CVE-2026-84890 / GHSA-3xpg-4rpp-hhhm
More information
Details
Impact
The
interceptors.decompress()interceptor decompresses HTTP response bodies according to the untrustedContent-Encodingheader. The number of decompression layers is capped at 5, but the total decompressed output size is not bounded and there is no option to limit it. A malicious or faulty upstream can return a small compressed payload (a compression bomb) that expands to hundreds of megabytes or gigabytes in client memory, exhausting memory and causing the Node.js process to crash or become unresponsive. Any application using the decompress interceptor to read responses from untrusted or compromised upstreams is affected.Patches
Upgrade to
7.29.1or8.10.2. The interceptor now accepts amaxSizeoption (default 64 MiB) and rejects responses whose decompressed output exceeds it with aResponseExceededMaxSizeError.Workarounds
Once upgraded, set a conservative
maxSizeon the interceptor. Before upgrading, avoid usinginterceptors.decompress()with untrusted upstreams, or apply a custom interceptor that enforces a decompressed output size limit.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to Denial of Service via unrequested WebSocket subprotocol
CVE-2026-19534 / GHSA-rfgv-xxqx-mfg5
More information
Details
Impact
The undici WebSocket client throws an uncaught
TypeErrorduring the opening handshake when a server's101response includes aSec-WebSocket-Protocolheader that the client never requested. The throw occurs in aqueueMicrotaskcallback with no surroundingtry/catch, so it propagates as an uncaught exception and terminates the Node.js process. This is a remote, unauthenticated denial of service against any application that opens a WebSocket to an attacker controlled or compromised server, or over a plaintextws://connection subject to a machine-in-the-middle. It affects the defaultnew WebSocket(url)usage, where no subprotocol is requested. Per RFC 6455 section 4.1, an unrequested subprotocol must fail the connection, not crash it.All releases starting at undici 6.7.0 are affected.
Patches
Upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
Workarounds
No workaround is available. The fix must be applied through an upgrade.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to downstream response splitting via retry interceptor
CVE-2026-18540 / GHSA-r53p-7pc4-xj5r
More information
Details
Impact
Undici's
interceptors.retry()can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried aContent-Length, the application can receive a longer body. Applications that forward Undici's status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwardedContent-Length, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).For example, a
404 Not FoundwithContent-Length: 2that sends one byte then closes can be resumed with an open-endedRangerequest, and the resumed206 Partial Contentbytes are appended, so the application receives more than two body bytes while still seeingContent-Length: 2. The bug requiresinterceptors.retry()enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculateContent-Length.Patches
Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.
Workarounds
interceptors.retry()for untrusted upstreams, or setmaxRetries: 0.Content-Lengthbefore forwarding a response body assembled by Undici.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to Denial of Service via orphaned RetryHandler response body
CVE-2026-18149 / GHSA-pmjh-fq2x-6v4x
More information
Details
Impact
undici's
RetryHandlercan leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the originalresponse.bodyheld by the application is never settled, so reads such asresponse.body.text()hang andbodyTimeoutdoes not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.Patches
Patched in undici v7.29.1 and v8.10.2.
Workarounds
Impose an independent request deadline and destroy the response body when it expires.
bodyTimeoutalone does not prevent this.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
bump,lockfileUpdate, orrollbackupdates, so these are raised without a Minimum Release Age check. You will need to manually validate the Minimum Release Age for these package(s).Release Notes
nodejs/undici (undici@<6.23.0)
v8.10.2Compare Source
High severity
BalancedPoolcould drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preservesconnectand legacytlsoptions when creating upstreams. Fixed by 8f5868fb.TypeErrorthat could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 66e12816.Medium severity
WebSocketStreamclose could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 662d0ea6.Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by cb75bbb3.maxSize. Fixed by 7aac7f12.Low severity
POSTorDELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by 2be07bf9.Content-Lengthwas present. Undici now enforcesmaxSizeagainst received bytes and aborts oversized responses. Fixed by 6d583124.Content-Rangeagainst the original response framing before resuming. Fixed by 0160a719.What's Changed
New Contributors
Full Changelog: nodejs/undici@v8.10.1...v8.10.2
v8.10.1Compare Source
Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.