GHSA-3xpg-4rpp-hhhm: Medium severity npm/undici vulnerability

Published Sep 29, 2026
·
Updated

Impact

The interceptors.decompress() interceptor decompresses HTTP response bodies according to the untrusted Content-Encoding header. The number of decompression layers is capped at 5, but the total decompressed output size is not bounded and there is no option to limit it. A malicious or faulty upstream can return a small compressed payload (a compression bomb) that expands to hundreds of megabytes or gigabytes in client memory, exhausting memory and causing the Node.js process to crash or become unresponsive. Any application using the decompress interceptor to read responses from untrusted or compromised upstreams is affected.

Patches

Upgrade to 7.29.1 or 8.10.2. The interceptor now accepts a maxSize option (default 64 MiB) and rejects responses whose decompressed output exceeds it with a ResponseExceededMaxSizeError.

Workarounds

Once upgraded, set a conservative maxSize on the interceptor. Before upgrading, avoid using interceptors.decompress() with untrusted upstreams, or apply a custom interceptor that enforces a decompressed output size limit.

Affected Software

2 affected componentsFixes available
npm/undici>=8.0.0<8.10.2
8.10.2
npm/undici>=7.15.0<7.29.1
7.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 7.29.1
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.10.2
  5. Configuration

    Set a conservative maxSize for decompressed output; the interceptor default is 64 MiB and responses exceeding the limit are rejected.

    interceptors.decompress() maxSize = 64 MiB
  6. Compensating control

    Before upgrading, avoid using interceptors.decompress() with untrusted upstreams, or use a custom interceptor that enforces a decompressed output size limit.

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:20 PM
Data Sourced
via GitHub·06:20 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are realistically exposed to this issue?

Applications using the `interceptors.decompress()` interceptor to read HTTP responses from untrusted or compromised upstreams are affected. A malicious or faulty upstream can send a small compressed response that expands until the Node.js process exhausts memory.

2

Does exploitation require authentication or user interaction?

No. The supplied vector lists network access with no privileges or user interaction required, though exploitation has high attack complexity. The attacker needs to control, compromise, or otherwise cause a targeted upstream to return a compression bomb with a `Content-Encoding` header.

3

What changes after upgrading, and how should the limit be configured?

Upgrade to `7.29.1` or `8.10.2`, where the interceptor supports `maxSize` and defaults it to 64 MiB. Set `maxSize` to a conservative value appropriate for the application; oversized decompressed responses are rejected with `ResponseExceededMaxSizeError`.

4

What can be done if an upgrade cannot be applied immediately?

Do not use `interceptors.decompress()` for responses from untrusted upstreams. Alternatively, use a custom interceptor that enforces a limit on the decompressed output size.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203