GHSA-r53p-7pc4-xj5r: Low severity npm/undici vulnerability
Impact
Undici's interceptors.retry() can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried a Content-Length, the application can receive a longer body. Applications that forward Undici's status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwarded Content-Length, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).
For example, a 404 Not Found with Content-Length: 2 that sends one byte then closes can be resumed with an open-ended Range request, and the resumed 206 Partial Content bytes are appended, so the application receives more than two body bytes while still seeing Content-Length: 2. The bug requires interceptors.retry() enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculate Content-Length.
Patches
Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.
Workarounds
- Disable interceptors.retry() for untrusted upstreams, or set maxRetries: 0. - Remove or recalculate Content-Length before forwarding a response body assembled by Undici.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 6.28.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 6.28.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Configuration
Disable interceptors.retry() for untrusted upstreams, or configure maxRetries: 0.
Undici interceptors.retry() = disabled or maxRetries: 0 - Configuration
Remove or recalculate Content-Length before forwarding a response body assembled by Undici.
Applications forwarding Undici responses Content-Length = removed or recalculated
Event History
Frequently Asked Questions
Which deployments are realistically exposed to this issue?
Applications are exposed when they enable Undici's interceptors.retry(), communicate with an attacker-controlled or faulty upstream, and forward the upstream status, headers, and body downstream without recalculating Content-Length. Proxy and gateway applications are specifically at risk.
What does an attacker need to trigger the issue?
The attacker needs control of, or the ability to induce faulty behavior from, an upstream that returns a partial response and closes the connection. Retry processing must then resume the request and append resumed response bytes while the forwarding application retains the original response framing.
Are applications affected by default?
The described condition requires interceptors.retry() to be enabled. The available information does not establish that this interceptor is enabled by default.
What can be done if an upgrade cannot be applied immediately?
Avoid forwarding Undici response headers and body unchanged when retry interception is enabled. Recalculate Content-Length for the body actually delivered downstream, or avoid using interceptors.retry() in affected forwarding paths.
Which versions contain fixes?
Fixes are available in Undici v6.28.1, v7.29.1, and v8.10.2.