GHSA-8xcm-r25x-g524: Medium severity npm/undici vulnerability
Impact
Undici's interceptors.retry() can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. Applications that use interceptors.retry() and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale Content-Length header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata.
A malicious or faulty upstream can respond to a range request with a 206 Partial Content response such as:
http Content-Range: bytes 0-99/300 Content-Length: 300
and then send only 99 bytes before closing the socket. interceptors.retry() can then retry with Range: bytes=99-99, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain Content-Length: 300 from the first response.
The bug requires interceptors.retry() to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate Content-Length.
Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.
Workarounds
- Disable interceptors.retry() for untrusted upstreams. - Remove or recalculate Content-Length before forwarding a response body assembled or transformed by Undici.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 8.9.0 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 7.29.0 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 6.28.0 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 6.28.0 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 7.29.0 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.9.0 - Configuration
Disable interceptors.retry() for untrusted upstreams to prevent forwarding of stale/mismatched framing metadata from partial (206) responses.
Undici (interceptors.retry) interceptors.retry() = disabled for untrusted upstreams - Configuration
Remove or recalculate Content-Length before forwarding any response body assembled or transformed by Undici, especially for responses assembled via interceptors.retry().
Undici (proxy/gateway forwarding) Content-Length = remove or recalculate before forwarding
Event History
Frequently Asked Questions
What is the severity of GHSA-8xcm-r25x-g524?
The severity of GHSA-8xcm-r25x-g524 is medium with a score of 4.8.
What impact does GHSA-8xcm-r25x-g524 have on applications?
GHSA-8xcm-r25x-g524 can cause a mismatch between the response body length and the `Content-Length` header in applications using `interceptors.retry()`.
How can I mitigate the risks associated with GHSA-8xcm-r25x-g524?
To mitigate GHSA-8xcm-r25x-g524, ensure you validate the response body length against the `Content-Length` header after using `interceptors.retry()`.
Which software is affected by GHSA-8xcm-r25x-g524?
GHSA-8xcm-r25x-g524 affects the npm package `undici`.
When was GHSA-8xcm-r25x-g524 published?
GHSA-8xcm-r25x-g524 was published on August 3, 2026.