Skip to content

chore(deps): update dependency undici to v7.29.0 [security] - #10296

Open
backstage-goalie[bot] wants to merge 1 commit into
mainfrom
renovate/npm-undici-vulnerability
Open

chore(deps): update dependency undici to v7.29.0 [security]#10296
backstage-goalie[bot] wants to merge 1 commit into
mainfrom
renovate/npm-undici-vulnerability

Conversation

@backstage-goalie

@backstage-goalie backstage-goalie Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
undici (source) 7.28.07.29.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

CVE-2026-13697 / GHSA-4cwx-7wf7-3272

More information

Details

Summary

Two issues in undici's cache interceptor, both fixed by the same patch on lib/util/cache.js:

  1. Shared-cache disclosure: Responses with malformed qualified Cache-Control: private directives such as private="" or private="," can be incorrectly stored in the default shared cache, then served to a later caller with the same cache key.
  2. Parse-time crash: Mixed unqualified-and-qualified private directives in the same header (such as public, max-age=60, private, private="hdr") cause an uncaught TypeError in the cache-control parser, terminating the request.
Impact
Shared-cache disclosure

Applications using interceptors.cache() in shared mode may cache a user-specific response and serve it to a later caller with the same cache key. This can disclose private response bodies and headers, including Set-Cookie.

Required conditions:

  • the cache interceptor is enabled in shared mode, including the default configuration;
  • an upstream returns a malformed directive such as Cache-Control: public, max-age=300, private="";
  • another request later matches the same cache key, without a separating Vary header.
Parse-time crash

Applications using interceptors.cache() against an upstream that returns a Cache-Control header combining unqualified private with qualified private="..." see an uncaught TypeError: output.private.concat is not a function during response handling. The request rejects; depending on the consumer's error handling, the process may exit.

Details

private="" is parsed as { private: [''] }. The shared-cache guard only rejects private === true, so the response can be stored. When served from cache, the previous user's body and headers may be returned to a different user.

For the crash variant, an unqualified private directive sets output.private = true, then a subsequent qualified private="hdr" directive attempts output.private.concat(['hdr']), which throws because boolean has no concat method.

The patch routes the qualified-directive path through a shared helper that normalizes empty-after-trim arrays to true and preserves existing true values, closing both vectors.

Patches

Upgrade to undici 7.29.0 or 8.9.0. Both releases fix the qualified private directive handling that caused the shared-cache storage and the parser crash.

Workarounds

Until patched, avoid shared interceptors.cache() for user-specific responses, use type: 'private', or disable caching for affected origins.

Credit

Disclosure variant reported by @​h0rk1p via HackerOne report #​3817497.

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


undici vulnerable to downstream response desynchronization via retry interceptor

CVE-2026-16728 / GHSA-8xcm-r25x-g524

More information

Details

Impact

Undici's interceptors.retry() can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. Applications that use interceptors.retry() and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale Content-Length header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata.

A malicious or faulty upstream can respond to a range request with a 206 Partial Content response such as:

Content-Range: bytes 0-99/300
Content-Length: 300

and then send only 99 bytes before closing the socket. interceptors.retry() can then retry with Range: bytes=99-99, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain Content-Length: 300 from the first response.

The bug requires interceptors.retry() to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate Content-Length.

Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.

Workarounds
  • Disable interceptors.retry() for untrusted upstreams.
  • Remove or recalculate Content-Length before forwarding a response body assembled or transformed by Undici.

Severity

  • CVSS Score: 4.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

CVE-2026-14643 / GHSA-jr45-8vmc-qm54

More information

Details

Impact

Undici's cache interceptor mishandles optional whitespace (OWS) placed around the = of a qualified no-cache or private Cache-Control directive, such as no-cache ="authorization" (OWS before =) or no-cache= "authorization" (OWS after =). The parser either drops the directive entirely or stores a field name with literal quote characters, so the downstream cache decisions do not recognize the qualification and the response is stored.

In shared-cache mode, this allows a response containing one user's authenticated data to be served from cache to a subsequent caller, including an unauthenticated caller, when both requests resolve to the same cache key. The impact class is identical to CVE-2026-9678 (GHSA-pr7r-676h-xcf6); this advisory covers the whitespace-around-= bypass that the earlier fix did not normalize.

Affected applications are those that explicitly enable the cache interceptor (interceptors.cache()) in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified private or no-cache directives whose field-name list is padded with OWS around the =.

Patches

Upgrade to undici v7.29.0 or v8.9.0.

Workarounds

If upgrade is not immediately possible, disable shared-cache mode for traffic that includes Authorization headers, avoid caching responses to authenticated requests, or add Vary: Authorization upstream.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


undici vulnerable to CRLF Injection via blob-like body 'type' property

CVE-2026-15157 / GHSA-m8rv-5g2x-5cg5

More information

Details

Impact

When an application passes a duck-typed blob-like body to undici's HTTP/1.1 dispatcher (via request(), stream(), pipeline(), or dispatch()) with a .type derived from untrusted input, an attacker can inject CRLF sequences (\r\n) to append arbitrary HTTP headers and potentially smuggle a second request past the upstream.

The vulnerable branch in lib/dispatcher/client-h1.js pushes body.type directly into the outgoing headers with no validation, while every other header path in undici goes through isValidHeaderValue():

} else if (util.isBlobLike(body) && request.contentType == null && body.type) {
  headers.push('content-type', body.type)  // bypasses isValidHeaderValue()
}

The bug requires a hand-rolled duck-typed blob object or a Blob subclass with a controlled .type. Native Blob is safe because its constructor strips CRLF from .type. fetch() is unaffected because it validates via the Headers class. Ecosystem consumers that build duck-typed blob shapes from user input include form-data-encoder, formdata-polyfill, and formdata-node.

Same defect class as CVE-2022-35948 (explicit content-type sink, fixed in undici 5.8.2) and CVE-2026-1527 (upgrade option sink, fixed in 6.24.0 / 7.24.0), both closed by adding isValidHeaderValue() on their respective sinks. This branch was missed.

Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.

Workarounds
  • Set an explicit, validated content-type header on the request options (skips the vulnerable branch).
  • Use a native Blob (or fetch-blob) instead of a hand-rolled duck-typed object.
  • Reject control characters in the MIME type before assigning it to .type.
  • Use fetch() instead of the non-fetch APIs.

Severity

  • CVSS Score: 4.2 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

CVE-2026-16729 / GHSA-v3r7-h72x-cjcm

More information

Details

Impact

The setCookie function has two attribute injection paths. validateCookieDomain does not reject semicolons (validateCookiePath already does at 0x3B), so a domain value like example.com; SameSite=None lands verbatim as Domain=example.com; SameSite=None. The unparsed array's loop only checks each entry contains = and does not sanitize values, so an entry like X-Custom=val; HttpOnly lands unchanged, injecting HttpOnly without the caller setting cookie.httpOnly = true.

Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, Secure or HttpOnly forced or stripped, or the intended SameSite tier overridden.

Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0.

Workarounds
  • Sanitize domain values against the RFC 1034 letter-digit-hyphen set before passing to setCookie.
  • Do not pass user-controlled data to the unparsed field.

Severity

  • CVSS Score: 4.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nodejs/undici (undici)

v7.29.0

Compare Source

⚠️ Security fixes

High severity
  • GHSA-4cwx-7wf7-3272: malformed qualified private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 9f10f1e9, with regression coverage in 466e99d1.
Medium severity
  • GHSA-m8rv-5g2x-5cg5: a malicious type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 33928bc2.
  • GHSA-jr45-8vmc-qm54: optional whitespace around = in qualified no-cache and private directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by 98011a86.
  • GHSA-8xcm-r25x-g524: the retry interceptor could expose a stale Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by 1b5a5312, with corrected fixtures in 4a9dafb1.
  • GHSA-v3r7-h72x-cjcm: unsanitized domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 3bf91ddb.

Full Changelog: nodejs/undici@v7.28.0...v7.29.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@backstage-goalie backstage-goalie Bot added dependencies Pull requests that update a dependency file security labels Aug 11, 2026
@backstage-goalie
backstage-goalie Bot requested a review from 04kash August 11, 2026 18:48
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch 3 times, most recently from 0e72b9b to 36ff4a9 Compare August 11, 2026 21:36
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] chore(deps): update dependency undici to v7.29.0 [security] - autoclosed Aug 12, 2026
@backstage-goalie backstage-goalie Bot closed this Aug 12, 2026
@backstage-goalie
backstage-goalie Bot deleted the renovate/npm-undici-vulnerability branch August 12, 2026 04:41
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] - autoclosed chore(deps): update dependency undici to v7.29.0 [security] Aug 12, 2026
@backstage-goalie backstage-goalie Bot reopened this Aug 12, 2026
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch 4 times, most recently from 346ec1f to cac9f2b Compare August 12, 2026 18:01
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] chore(deps): update dependency undici to v7.29.0 [security] - autoclosed Aug 12, 2026
@backstage-goalie backstage-goalie Bot closed this Aug 12, 2026
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] - autoclosed chore(deps): update dependency undici to v7.29.0 [security] Aug 12, 2026
@backstage-goalie backstage-goalie Bot reopened this Aug 12, 2026
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch 3 times, most recently from eb55365 to f77abca Compare August 12, 2026 22:25
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] chore(deps): update dependency undici to v7.29.0 [security] - autoclosed Aug 13, 2026
@backstage-goalie backstage-goalie Bot closed this Aug 13, 2026
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] - autoclosed chore(deps): update dependency undici to v7.29.0 [security] Aug 13, 2026
@backstage-goalie backstage-goalie Bot reopened this Aug 13, 2026
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch 4 times, most recently from 5431684 to 2d1b408 Compare August 13, 2026 13:44
@backstage-goalie backstage-goalie Bot changed the title chore(deps): update dependency undici to v7.29.0 [security] Update dependency undici to v7.29.0 [SECURITY] Aug 13, 2026
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch from 2d1b408 to cb669bf Compare August 13, 2026 14:51
@backstage-goalie backstage-goalie Bot changed the title Update dependency undici to v7.29.0 [SECURITY] chore(deps): update dependency undici to v7.29.0 [security] Aug 13, 2026
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch 3 times, most recently from 9821fd6 to 71c14ee Compare August 14, 2026 13:38
Signed-off-by: Renovate Bot <bot@renovateapp.com>
@backstage-goalie
backstage-goalie Bot force-pushed the renovate/npm-undici-vulnerability branch from 71c14ee to cb39306 Compare August 14, 2026 15:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security workspace/argocd

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant