Vulnerability GHSA-pmjh-fq2x-6v4x

Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 hour ago
September 29, 2026 at 06:22 PM UTC
undici vulnerable to Denial of Service via orphaned RetryHandler response body
7.11.0 - 7.29.0 and 8.0.0 - 8.10.1
7.11.0 - 7.29.0 and 8.0.0 - 8.10.1

Summary

undici vulnerable to Denial of Service via orphaned RetryHandler response body

Details

Impact

undici's RetryHandler can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original response.body held by the application is never settled, so reads such as response.body.text() hang and bodyTimeout does not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.

Patches

Patched in undici v7.29.1 and v8.10.2.

Workarounds

Impose an independent request deadline and destroy the response body when it expires. bodyTimeout alone does not prevent this.

Impacted packages

Timeline

Published
1 hour ago
September 29, 2026 at 06:22 PM UTC
Fixed (8.10.2)
25 days ago
September 04, 2026 at 02:00 PM UTC
Fixed (7.29.1)
25 days ago
September 04, 2026 at 02:25 PM UTC
Last Modified
1 hour ago
September 29, 2026 at 06:30 PM UTC