GHSA-2gqq-gqf2-x968: Input Validation

Published Sep 29, 2026
·
Updated

Impact

undici's interceptors.dump() reads and discards response bodies up to a configurable maxSize. When a response declares a Content-Length that exceeds maxSize, the request is aborted cleanly. When a response is sent chunked (no Content-Length) and its body exceeds maxSize, it is not aborted: the interceptor ends the response early once the accumulated size reaches maxSize, and continued delivery from the parser triggers an internal assertion that is caught and turned into a request abort and connection tear-down. The application observes a misleading 200 with an empty or truncated body while the connection is disconnected. Any application using the dump interceptor against untrusted or misbehaving upstreams is affected.

Patches

Upgrade to 7.29.1 or 8.10.2. The dump interceptor now enforces maxSize on both the declared and the received body size, aborting the request with a RequestAbortedError instead of returning a truncated response.

Workarounds

None. Avoid using interceptors.dump() with untrusted upstreams until upgraded.

Affected Software

2 affected componentsFixes available
npm/undici>=8.0.0<8.10.2
8.10.2
npm/undici>=7.1.0<7.29.1
7.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  3. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  5. Compensating control

    Avoid using undici's interceptors.dump() with untrusted upstreams until upgraded.

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:18 PM
Data Sourced
via GitHub·06:18 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Applications using undici's interceptors.dump() while communicating with untrusted or misbehaving upstream servers are affected. The issue is triggered when an upstream sends a chunked response without Content-Length whose received body exceeds the configured maxSize.

2

What does successful exploitation look like to the application?

The application can receive a misleading HTTP 200 response with an empty or truncated body. The underlying connection is then disconnected after an internal assertion is caught and converted into a request abort.

3

Are there mitigations if an upgrade cannot be applied immediately?

No workaround is provided. Avoid using interceptors.dump() with untrusted upstreams until upgrading.

4

Which versions contain the fix?

Upgrade to undici 7.29.1 or 8.10.2. The corrected behavior enforces maxSize against received body size as well as declared Content-Length and returns a RequestAbortedError rather than a truncated response.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203