GHSA-w293-vg96-wgc3: High severity npm/undici vulnerability

Published Sep 29, 2026
·
Updated

Impact

undici's BalancedPool passes its constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstream Pool. JSON cannot represent functions, so a caller-supplied connect or tls option containing a checkServerIdentity callback (or a custom connector function) is silently dropped before it reaches the TLS layer. As a result, a TLS peer whose certificate a custom checkServerIdentity was written to reject, but which passes Node's default hostname and chain checks, is silently accepted when the request is made through BalancedPool. Client, Pool, Agent, and RoundRobinPool destructure connect/tls before the clone and are not affected. Only applications that use BalancedPool with a function-valued connect/tls option (such as a custom checkServerIdentity or connector) are affected.

Patches

Upgrade to 7.29.1 or 8.10.2. BalancedPool now preserves the connect and tls options outside the JSON clone, so custom TLS verification callbacks are forwarded to each upstream unchanged.

Workarounds

Use Client, Pool, or Agent instead of BalancedPool for connections that rely on a custom checkServerIdentity or connector, until upgraded.

Affected Software

2 affected componentsFixes available
npm/undici>=8.0.0<8.10.2
8.10.2
npm/undici>=7.24.1<7.29.1
7.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  3. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 7.29.1
  4. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  5. Compensating control

    Use Client, Pool, or Agent instead of BalancedPool for connections that rely on a custom checkServerIdentity callback or connector until upgraded.

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:17 PM
Data Sourced
via GitHub·06:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Only applications using undici's BalancedPool with function-valued connect or tls options are affected. This includes a custom checkServerIdentity callback or custom connector function; Client, Pool, Agent, and RoundRobinPool are not affected.

2

What certificate conditions are required for exploitation?

The TLS peer certificate must pass Node's default hostname and certificate-chain validation but fail the application's custom checkServerIdentity logic. Because BalancedPool drops that callback, the peer can be accepted despite the intended additional verification.

3

Are default BalancedPool configurations affected?

No. The issue requires function-valued connect or tls options supplied to BalancedPool; the affected functions are lost during its JSON-based option cloning.

4

What can be done if an upgrade cannot be applied immediately?

Use Client, Pool, or Agent instead of BalancedPool for connections that rely on custom TLS verification or a custom connector. These components preserve the relevant options before cloning.

5

Which versions contain the fix?

Upgrade undici to version 7.29.1 or 8.10.2. The fix preserves connect and tls options outside the JSON clone so they are forwarded unchanged to each upstream.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203