GHSA-r53p-7pc4-xj5r: Low severity npm/undici vulnerability

Published Sep 29, 2026
·
Updated

Impact

Undici's interceptors.retry() can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried a Content-Length, the application can receive a longer body. Applications that forward Undici's status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwarded Content-Length, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).

For example, a 404 Not Found with Content-Length: 2 that sends one byte then closes can be resumed with an open-ended Range request, and the resumed 206 Partial Content bytes are appended, so the application receives more than two body bytes while still seeing Content-Length: 2. The bug requires interceptors.retry() enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculate Content-Length.

Patches

Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.

Workarounds

- Disable interceptors.retry() for untrusted upstreams, or set maxRetries: 0. - Remove or recalculate Content-Length before forwarding a response body assembled by Undici.

Affected Software

3 affected componentsFixes available
npm/undici>=8.0.0<8.10.2
8.10.2
npm/undici>=7.0.0<7.29.1
7.29.1
npm/undici<6.28.1
6.28.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  3. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 6.28.1
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 6.28.1
  5. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  6. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  7. Configuration

    Disable interceptors.retry() for untrusted upstreams, or configure maxRetries: 0.

    Undici interceptors.retry() = disabled or maxRetries: 0
  8. Configuration

    Remove or recalculate Content-Length before forwarding a response body assembled by Undici.

    Applications forwarding Undici responses Content-Length = removed or recalculated

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:22 PM
Data Sourced
via GitHub·06:22 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are realistically exposed to this issue?

Applications are exposed when they enable Undici's interceptors.retry(), communicate with an attacker-controlled or faulty upstream, and forward the upstream status, headers, and body downstream without recalculating Content-Length. Proxy and gateway applications are specifically at risk.

2

What does an attacker need to trigger the issue?

The attacker needs control of, or the ability to induce faulty behavior from, an upstream that returns a partial response and closes the connection. Retry processing must then resume the request and append resumed response bytes while the forwarding application retains the original response framing.

3

Are applications affected by default?

The described condition requires interceptors.retry() to be enabled. The available information does not establish that this interceptor is enabled by default.

4

What can be done if an upgrade cannot be applied immediately?

Avoid forwarding Undici response headers and body unchanged when retry interception is enabled. Recalculate Content-Length for the body actually delivered downstream, or avoid using interceptors.retry() in affected forwarding paths.

5

Which versions contain fixes?

Fixes are available in Undici v6.28.1, v7.29.1, and v8.10.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203