CVE-2026-16728: undici vulnerable to downstream response desynchronization via retry interceptor
Impact
Undici's interceptors.retry() can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. Applications that use interceptors.retry() and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale Content-Length header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata.
A malicious or faulty upstream can respond to a range request with a 206 Partial Content response such as:
http Content-Range: bytes 0-99/300 Content-Length: 300
and then send only 99 bytes before closing the socket. interceptors.retry() can then retry with Range: bytes=99-99, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain Content-Length: 300 from the first response.
The bug requires interceptors.retry() to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate Content-Length.
Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.
Workarounds
- Disable interceptors.retry() for untrusted upstreams. - Remove or recalculate Content-Length before forwarding a response body assembled or transformed by Undici.
Other sources
undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a malicious or faulty upstream can return a partial response with a mismatched framing header, close the socket early, and have the retry interceptor assemble a body of a different length while the original Content-Length stays attached. Applications that use the retry interceptor and forward upstream headers and bodies downstream, such as proxies or gateways, may then emit an invalid HTTP response with a stale Content-Length, leading to downstream response desynchronization, connection hangs, or response corruption. Exploitation requires the retry interceptor enabled, an upstream returning a mismatched partial response, and a downstream forwarder that does not remove or recalculate Content-Length. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 8.9.0 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 7.29.0 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 6.28.0 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 6.28.0 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 7.29.0 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.9.0 - Configuration
Disable interceptors.retry() for untrusted upstreams.
undici interceptors.retry() interceptors.retry() = disabled - Configuration
Before forwarding a response body assembled or transformed by Undici, remove or recalculate Content-Length so it matches the forwarded body length.
Undici proxy/gateway forwarder behavior Content-Length handling = remove or recalculate
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16728?
The severity of CVE-2026-16728 is medium with a score of 4.8.
How do I fix CVE-2026-16728?
To fix CVE-2026-16728, update undici to version 6.28.0 or later.
What types of systems are affected by CVE-2026-16728?
CVE-2026-16728 affects applications using the undici library for HTTP/1.1 client requests.
What is the exploit mechanism for CVE-2026-16728?
CVE-2026-16728 can be exploited through a downstream response desynchronization via the retry interceptor.
Is CVE-2026-16728 a critical vulnerability?
CVE-2026-16728 is not classified as critical; it holds a medium severity rating.