GHSA-w293-vg96-wgc3: High severity npm/undici vulnerability
Impact
undici's BalancedPool passes its constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstream Pool. JSON cannot represent functions, so a caller-supplied connect or tls option containing a checkServerIdentity callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom checkServerIdentity was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through BalancedPool. Client, Pool, Agent, and RoundRobinPool destructure connect/tls before the clone and are not affected. Only applications that use BalancedPool with a function-valued connect/tls option (such as a custom checkServerIdentity or connector) are affected.
Patches
Upgrade to 7.29.1 or 8.10.2. BalancedPool now preserves the connect and tls options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.
Workarounds
Use Client, Pool, or Agent instead of BalancedPool for connections that rely on a custom checkServerIdentity or connector, until upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Upgrade
Upgrade
npm/undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 7.29.1 - Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.10.2 - Compensating control
Use Client, Pool, or Agent instead of BalancedPool for connections that rely on a custom checkServerIdentity callback or connector until upgraded.
Event History
Frequently Asked Questions
Which deployments are affected?
Only applications using undici's BalancedPool with function-valued connect or tls options are affected. This includes a custom checkServerIdentity callback or custom connector function; Client, Pool, Agent, and RoundRobinPool are not affected.
What certificate conditions are required for exploitation?
The TLS peer certificate must pass Node's default hostname and certificate-chain validation but fail the application's custom checkServerIdentity logic. Because BalancedPool drops that callback, the peer can be accepted despite the intended additional verification.
Are default BalancedPool configurations affected?
No. The issue requires function-valued connect or tls options supplied to BalancedPool; the affected functions are lost during its JSON-based option cloning.
What can be done if an upgrade cannot be applied immediately?
Use Client, Pool, or Agent instead of BalancedPool for connections that rely on custom TLS verification or a custom connector. These components preserve the relevant options before cloning.
Which versions contain the fix?
Upgrade undici to version 7.29.1 or 8.10.2. The fix preserves connect and tls options outside the JSON clone so they are forwarded unchanged to each upstream.