GHSA-pmjh-fq2x-6v4x: Medium severity npm/undici vulnerability

Published Sep 29, 2026
·
Updated

Impact

undici's RetryHandler can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original response.body held by the application is never settled, so reads such as response.body.text() hang and bodyTimeout does not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.

Patches

Patched in undici v7.29.1 and v8.10.2.

Workarounds

Impose an independent request deadline and destroy the response body when it expires. bodyTimeout alone does not prevent this.

Affected Software

2 affected componentsFixes available
npm/undici>=8.0.0<8.10.2
8.10.2
npm/undici>=7.11.0<7.29.1
7.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  3. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  5. Compensating control

    Impose an independent request deadline and destroy the response body when the deadline expires; do not rely on bodyTimeout alone.

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:22 PM
Data Sourced
via GitHub·06:22 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What conditions are required for exploitation?

An application must use undici's RetryHandler and retain or read the original response body after a truncated response is retried. A malicious server must cause the truncated response and then return a non-retryable response to the retry attempt.

2

What is the practical impact on an affected application?

Reads from the original response body, such as response.body.text(), can remain pending indefinitely because the body is never settled. Repeated malicious responses can accumulate pending promises and streams, causing denial of service.

3

Which versions contain the fix?

The issue is patched in undici v7.29.1 and v8.10.2.

4

What can be done before patching?

Enforce an independent request deadline and destroy the response body when that deadline expires. bodyTimeout alone does not mitigate the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203