Repository navigation
chore(deps): update dependency undici@<6.27.0 to v8 [security] - #191
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Deploying auth-wiki with
|
| Latest commit: |
a059ad1
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://9d18bc98.auth-wiki.pages.dev |
| Branch Preview URL: | https://renovate-npm-undici-6-27-0-v.auth-wiki.pages.dev |
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 12, 2026 01:33
790d406 to
d69406a
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 12, 2026 09:56
d69406a to
68f18d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 14, 2026 17:38
68f18d4 to
a059ad1
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 14, 2026 23:52
a059ad1 to
dbf19ce
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 21, 2026 15:49
dbf19ce to
f6c7dfd
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 21, 2026 19:57
f6c7dfd to
07d40bd
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 22, 2026 15:55
07d40bd to
3f723cb
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 22, 2026 18:45
3f723cb to
7d2d628
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 26, 2026 15:42
7d2d628 to
9c4524b
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
August 27, 2026 00:03
9c4524b to
d1a9505
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 2, 2026 21:31
d1a9505 to
011a7d5
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 3, 2026 04:07
011a7d5 to
5e008d2
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 3, 2026 13:28
5e008d2 to
6d640b6
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 4, 2026 02:43
6d640b6 to
0499bb9
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 8, 2026 00:34
0499bb9 to
9b016b8
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 16, 2026 02:32
fbf5a5d to
a4a05c8
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 16, 2026 16:03
a4a05c8 to
9684c9c
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 16, 2026 20:59
9684c9c to
85c9b7f
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 17, 2026 17:29
85c9b7f to
07f6c14
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 17, 2026 23:22
07f6c14 to
f41bb45
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 18, 2026 20:30
f41bb45 to
4e094ed
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 19, 2026 01:51
4e094ed to
1448254
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 22, 2026 19:00
1448254 to
aaea08a
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 23, 2026 20:04
aaea08a to
07f7dde
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 24, 2026 05:12
07f7dde to
7705517
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 25, 2026 01:16
7705517 to
2a1dbdd
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 25, 2026 16:27
2a1dbdd to
6c7eff2
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
September 30, 2026 00:05
6c7eff2 to
8ecc25d
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-6.27.0-vulnerability
branch
from
October 1, 2026 04:19
8ecc25d to
164ee36
Compare
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^6.27.0→^8.10.2undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
CVE-2026-13697 / GHSA-4cwx-7wf7-3272
More information
Details
Summary
Two issues in undici's cache interceptor, both fixed by the same patch on
lib/util/cache.js:Cache-Control: privatedirectives such asprivate=""orprivate=","can be incorrectly stored in the default shared cache, then served to a later caller with the same cache key.privatedirectives in the same header (such aspublic, max-age=60, private, private="hdr") cause an uncaughtTypeErrorin the cache-control parser, terminating the request.Impact
Shared-cache disclosure
Applications using
interceptors.cache()in shared mode may cache a user-specific response and serve it to a later caller with the same cache key. This can disclose private response bodies and headers, includingSet-Cookie.Required conditions:
Cache-Control: public, max-age=300, private="";Varyheader.Parse-time crash
Applications using
interceptors.cache()against an upstream that returns aCache-Controlheader combining unqualifiedprivatewith qualifiedprivate="..."see an uncaughtTypeError: output.private.concat is not a functionduring response handling. The request rejects; depending on the consumer's error handling, the process may exit.Details
private=""is parsed as{ private: [''] }. The shared-cache guard only rejectsprivate === true, so the response can be stored. When served from cache, the previous user's body and headers may be returned to a different user.For the crash variant, an unqualified
privatedirective setsoutput.private = true, then a subsequent qualifiedprivate="hdr"directive attemptsoutput.private.concat(['hdr']), which throws because boolean has noconcatmethod.The patch routes the qualified-directive path through a shared helper that normalizes empty-after-trim arrays to
trueand preserves existingtruevalues, closing both vectors.Patches
Upgrade to
undici7.29.0 or 8.9.0. Both releases fix the qualifiedprivatedirective handling that caused the shared-cache storage and the parser crash.Workarounds
Until patched, avoid shared
interceptors.cache()for user-specific responses, usetype: 'private', or disable caching for affected origins.Credit
Disclosure variant reported by @h0rk1p via HackerOne report #3817497.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-16728 / GHSA-8xcm-r25x-g524
More information
Details
Impact
Undici's
interceptors.retry()can deliver a response whose body length does not match theContent-Lengthheader exposed to the application after a retry or resume of a partial response. Applications that useinterceptors.retry()and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a staleContent-Lengthheader. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata.A malicious or faulty upstream can respond to a range request with a
206 Partial Contentresponse such as:and then send only 99 bytes before closing the socket.
interceptors.retry()can then retry withRange: bytes=99-99, receive the final byte, and deliver a 100-byte body to the application while the response headers still containContent-Length: 300from the first response.The bug requires
interceptors.retry()to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculateContent-Length.Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.
Workarounds
interceptors.retry()for untrusted upstreams.Content-Lengthbefore forwarding a response body assembled or transformed by Undici.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVE-2026-16729 / GHSA-v3r7-h72x-cjcm
More information
Details
Impact
The
setCookiefunction has two attribute injection paths.validateCookieDomaindoes not reject semicolons (validateCookiePathalready does at 0x3B), so adomainvalue likeexample.com; SameSite=Nonelands verbatim asDomain=example.com; SameSite=None. Theunparsedarray's loop only checks each entry contains=and does not sanitize values, so an entry likeX-Custom=val; HttpOnlylands unchanged, injectingHttpOnlywithout the caller settingcookie.httpOnly = true.Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed,
SecureorHttpOnlyforced or stripped, or the intended SameSite tier overridden.Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0.
Workarounds
domainvalues against the RFC 1034 letter-digit-hyphen set before passing tosetCookie.unparsedfield.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
CVE-2026-14643 / GHSA-jr45-8vmc-qm54
More information
Details
Impact
Undici's cache interceptor mishandles optional whitespace (OWS) placed around the
=of a qualifiedno-cacheorprivateCache-Control directive, such asno-cache ="authorization"(OWS before=) orno-cache= "authorization"(OWS after=). The parser either drops the directive entirely or stores a field name with literal quote characters, so the downstream cache decisions do not recognize the qualification and the response is stored.In shared-cache mode, this allows a response containing one user's authenticated data to be served from cache to a subsequent caller, including an unauthenticated caller, when both requests resolve to the same cache key. The impact class is identical to CVE-2026-9678 (GHSA-pr7r-676h-xcf6); this advisory covers the whitespace-around-
=bypass that the earlier fix did not normalize.Affected applications are those that explicitly enable the cache interceptor (
interceptors.cache()) in shared mode, forwardAuthorizationheaders upstream, and receive cacheable responses with qualifiedprivateorno-cachedirectives whose field-name list is padded with OWS around the=.Patches
Upgrade to undici v7.29.0 or v8.9.0.
Workarounds
If upgrade is not immediately possible, disable shared-cache mode for traffic that includes
Authorizationheaders, avoid caching responses to authenticated requests, or addVary: Authorizationupstream.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-15157 / GHSA-m8rv-5g2x-5cg5
More information
Details
Impact
When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via
request(),stream(),pipeline(), ordispatch()) with a.typederived from untrusted input, an attacker can inject CRLF sequences (\r\n) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.The vulnerable branch in
lib/dispatcher/client-h1.jspushesbody.typedirectly into the outgoing headers with no validation, while every other header path in undici goes throughisValidHeaderValue():The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled
.type. NativeBlobis safe because its constructor strips CRLF from.type.fetch()is unaffected because it validates via theHeadersclass. Ecosystem consumers that build duck-typed blob shapes from user input includeform-data-encoder,formdata-polyfill, andformdata-node.Same defect class as
CVE-2022-35948(explicitcontent-typesink, fixed in undici 5.8.2) andCVE-2026-1527(upgradeoption sink, fixed in 6.24.0 / 7.24.0), both closed by addingisValidHeaderValue()on their respective sinks. This branch was missed.Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.
Workarounds
content-typeheader on the request options (skips the vulnerable branch).Blob(orfetch-blob) instead of a hand-rolled duck-typed object..type.fetch()instead of the non-fetchAPIs.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to caching and replay of unsafe HTTP method responses
CVE-2026-85008 / GHSA-8436-99hf-9mmv
More information
Details
Impact
undici's
interceptors.cache()documents that it caches only safe HTTP methods. However, its internal skip-list is built by subtracting the configured methods from the safe-methods set, so an unsafe method (POST,PUT,PATCH,DELETE) never lands in the skip-list and is looked up against the cache store. Combined with the storage gate (canCacheResponse) having no method check, a heuristically-cacheable response (for example a404) with an explicitCache-Control: max-age=...to an unsafe method is stored and replayed on a subsequent identical request. The application's state-changing request never reaches the origin, and undici serves a fabricated response from the cache instead. This occurs with the default configuration (methods: ['GET']), which the public API does not allow widening to unsafe methods, so no application misuse is required; an untrusted origin can trigger it purely through its own response headers.Patches
Upgrade to
7.29.1or8.10.2. The cache interceptor no longer reads from or writes to the cache for unsafe HTTP methods, while still invalidating existing cache entries on successful unsafe requests.Workarounds
None.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool
CVE-2026-84961 / GHSA-w293-vg96-wgc3
More information
Details
Impact
undici's
BalancedPoolpasses its constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstreamPool. JSON cannot represent functions, so a caller-suppliedconnectortlsoption containing acheckServerIdentitycallback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a customcheckServerIdentitywas written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made throughBalancedPool.Client,Pool,Agent, andRoundRobinPooldestructureconnect/tlsbefore the clone and are not affected. Only applications that useBalancedPoolwith a function-valuedconnect/tlsoption (such as a customcheckServerIdentityor connector) are affected.Patches
Upgrade to
7.29.1or8.10.2.BalancedPoolnow preserves theconnectandtlsoptions outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.Workarounds
Use
Client,Pool, orAgentinstead ofBalancedPoolfor connections that rely on a customcheckServerIdentityor connector, until upgraded.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches
CVE-2026-84933 / GHSA-2jfj-6hjv-fm6j
More information
Details
Impact
undici's
interceptors.cache()does not handleSet-Cookiein the cache path. In shared-cache mode (type: 'shared', the default), a cacheable response (for exampleCache-Control: public, max-age=...) carrying aSet-Cookieheader is stored, and the storedSet-Cookieis re-served to a later caller that hits the same cache key. This exposes one user's cookie to another caller and lets an untrusted upstream inject cookies into cached responses served to all subsequent callers, violating RFC 6265 section 7.2 (a shared cache must not store cookies). Applications using the shared cache interceptor against untrusted or multi-user upstreams are affected. Private caches (type: 'private') are not affected.Patches
Upgrade to
7.29.1or8.10.2. In shared-cache mode, undici no longer stores or re-serves responses containingSet-Cookie, including previously cached entries and revalidation paths.Workarounds
Use a private cache (
type: 'private') for per-user responses, or avoid caching responses that set cookies. Applications acting as shared caches should stripSet-Cookiefrom responses before caching.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to downstream response splitting via retry interceptor
CVE-2026-18540 / GHSA-r53p-7pc4-xj5r
More information
Details
Impact
Undici's
interceptors.retry()can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried aContent-Length, the application can receive a longer body. Applications that forward Undici's status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwardedContent-Length, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).For example, a
404 Not FoundwithContent-Length: 2that sends one byte then closes can be resumed with an open-endedRangerequest, and the resumed206 Partial Contentbytes are appended, so the application receives more than two body bytes while still seeingContent-Length: 2. The bug requiresinterceptors.retry()enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculateContent-Length.Patches
Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.
Workarounds
interceptors.retry()for untrusted upstreams, or setmaxRetries: 0.Content-Lengthbefore forwarding a response body assembled by Undici.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
CVE-2026-84947 / GHSA-2gqq-gqf2-x968
More information
Details
Impact
undici's
interceptors.dump()reads and discards response bodies up to a configurablemaxSize. When a response declares aContent-Lengththat exceedsmaxSize, the request is aborted cleanly. When a response is sent chunked (noContent-Length) and its body exceedsmaxSize, it is not aborted: the interceptor ends the response early once the accumulated size reachesmaxSize, and continued delivery from the parser triggers an internal assertion that is caught and turned into a request abort and connection tear-down. The application observes a misleading200with an empty or truncated body while the connection is disconnected. Any application using the dump interceptor against untrusted or misbehaving upstreams is affected.Patches
Upgrade to
7.29.1or8.10.2. The dump interceptor now enforcesmaxSizeon both the declared and the received body size, aborting the request with aRequestAbortedErrorinstead of returning a truncated response.Workarounds
None. Avoid using
interceptors.dump()with untrusted upstreams until upgraded.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
undici vulnerable to Denial of Service via orphaned RetryHandler response body
CVE-2026-18149 / GHSA-pmjh-fq2x-6v4x
More information
Details
Impact
undici's
RetryHandlercan leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the originalresponse.bodyheld by the application is never settled, so reads such asresponse.body.text()hang andbodyTimeoutdoes not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.Patches
Patched in undici v7.29.1 and v8.10.2.
Workarounds
Impose an independent request deadline and destroy the response body when it expires.
bodyTimeoutalone does not prevent this.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodejs/undici (undici@<6.27.0)
v8.10.2Compare Source
High severity
BalancedPoolcould drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preservesconnectand legacytlsoptions when creating upstreams. Fixed by 8f5868fb.TypeErrorthat could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 66e12816.Medium severity
WebSocketStreamclose could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 662d0ea6.Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by cb75bbb3.maxSize. Fixed by 7aac7f12.Low severity
POSTorDELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by 2be07bf9.Content-Lengthwas present. Undici now enforcesmaxSizeagainst received bytes and aborts oversized responses. Fixed by 6d583124.Content-Rangeagainst the original response framing before resuming. Fixed by 0160a719.What's Changed
New Contributors
Full Changelog: nodejs/undici@v8.10.1...v8.10.2
v8.10.1Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v8.10.0...v8.10.1
v8.10.0Compare Source
What's Changed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.