GHSA-pmjh-fq2x-6v4x: Medium severity npm/undici vulnerability
Impact
undici's RetryHandler can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original response.body held by the application is never settled, so reads such as response.body.text() hang and bodyTimeout does not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.
Patches
Patched in undici v7.29.1 and v8.10.2.
Workarounds
Impose an independent request deadline and destroy the response body when it expires. bodyTimeout alone does not prevent this.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Compensating control
Impose an independent request deadline and destroy the response body when the deadline expires; do not rely on bodyTimeout alone.
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An application must use undici's RetryHandler and retain or read the original response body after a truncated response is retried. A malicious server must cause the truncated response and then return a non-retryable response to the retry attempt.
What is the practical impact on an affected application?
Reads from the original response body, such as response.body.text(), can remain pending indefinitely because the body is never settled. Repeated malicious responses can accumulate pending promises and streams, causing denial of service.
Which versions contain the fix?
The issue is patched in undici v7.29.1 and v8.10.2.
What can be done before patching?
Enforce an independent request deadline and destroy the response body when that deadline expires. bodyTimeout alone does not mitigate the issue.