Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Sep 28, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
undici@>=4.5.0 <5.28.5 (source) [>=5.28.5>=6.23.0](https://renovatebot.com/diffs/npm/undici@&gt;&#x3D;4.5.0 <5.28.5/5.28.5/6.23.0) age confidence

GitHub Vulnerability Alerts

CVE-2023-45143

Impact

Undici clears Authorization headers on cross-origin redirects, but does not clear Cookie headers. By design, cookie headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since Undici handles headers more liberally than the specification, there was a disconnect from the assumptions the spec made, and Undici's implementation of fetch.

As such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.

Patches

This was patched in e041de359221ebeae04c469e8aff4145764e6d76, which is included in version 5.26.2.

CVE-2024-24758

Impact

Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authorization headers.

Patches

This is patched in v5.28.3 and v6.6.1

Workarounds

There are no known workarounds.

References

CVE-2024-30261

Impact

If an attacker can alter the integrity option passed to fetch(), they can let fetch() accept requests as valid even if they have been tampered.

Patches

Fixed in nodejs/undici@d542b8c.
Fixes has been released in v5.28.4 and v6.11.1.

Workarounds

Ensure that integrity cannot be tampered with.

References

https://hackerone.com/reports/2377760

CVE-2024-30260

Impact

Undici cleared Authorization and Proxy-Authorization headers for fetch(), but did not clear them for undici.request().

Patches

This has been patched in nodejs/undici@6805746.
Fixes has been released in v5.28.4 and v6.11.1.

Workarounds

use fetch() or disable maxRedirections.

References

Linzi Shang reported this.

CVE-2025-22150

Impact

Undici fetch() uses Math.random() to choose the boundary for a multipart/form-data request. It is known that the output of Math.random() can be predicted if several of its generated values are known.

If there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, An attacker can tamper with the requests going to the backend APIs if certain conditions are met.

Patches

This is fixed in 5.28.5; 6.21.1; 7.2.3.

Workarounds

Do not issue multipart requests to attacker controlled servers.

References

CVE-2022-31150

Impact

It is possible to inject CRLF sequences into request headers in Undici.

const undici = require('undici')

const response = undici.request("http://127.0.0.1:1000", {
  headers: {'a': "\r\nb"}
})

The same applies to path and method

Patches

Update to v5.8.0

Workarounds

Sanitize all HTTP headers from untrusted sources to eliminate \r\n.

References

https://hackerone.com/reports/409943
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12116

For more information

If you have any questions or comments about this advisory:

CVE-2022-31151

Impact

Authorization headers are already cleared on cross-origin redirect in
https://github.com/nodejs/undici/blob/main/lib/handler/redirect.js#L189, based on https://github.com/nodejs/undici/issues/872.

However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There also has been active discussion of implementing a cookie store https://github.com/nodejs/undici/pull/1441, which suggests that there are active users using cookie headers in undici.
As such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.

Patches

This was patched in v5.8.0.

Workarounds

By default, this vulnerability is not exploitable.
Do not enable redirections, i.e. maxRedirections: 0 (the default).

References

https://hackerone.com/reports/1635514
https://curl.se/docs/CVE-2018-1000007.html
https://curl.se/docs/CVE-2022-27776.html

For more information

If you have any questions or comments about this advisory:

CVE-2022-35949

Impact

undici is vulnerable to SSRF (Server-side Request Forgery) when an application takes in user input into the path/pathname option of undici.request.

If a user specifies a URL such as http://127.0.0.1 or //127.0.0.1

const undici = require("undici")
undici.request({origin: "http://example.com", pathname: "//127.0.0.1"})

Instead of processing the request as http://example.org//127.0.0.1 (or http://example.org/http://127.0.0.1 when http://127.0.0.1 is used), it actually processes the request as http://127.0.0.1/ and sends it to http://127.0.0.1.

If a developer passes in user input into path parameter of undici.request, it can result in an SSRF as they will assume that the hostname cannot change, when in actual fact it can change because the specified path parameter is combined with the base URL.

Patches

This issue was fixed in undici@5.8.1.

Workarounds

The best workaround is to validate user input before passing it to the undici.request call.

For more information

If you have any questions or comments about this advisory:

CVE-2022-35948

Impact

=< undici@5.8.0 users are vulnerable to CRLF Injection on headers when using unsanitized input as request headers, more specifically, inside the content-type header.

Example:

import { request } from 'undici'

const unsanitizedContentTypeInput =  'application/json\r\n\r\nGET /foo2 HTTP/1.1'

await request('http://localhost:3000, {
    method: 'GET',
    headers: {
      'content-type': unsanitizedContentTypeInput
    },
})

The above snippet will perform two requests in a single request API call:

  1. http://localhost:3000/
  2. http://localhost:3000/foo2

Patches

This issue was patched in Undici v5.8.1

Workarounds

Sanitize input when sending content-type headers using user input.

For more information

If you have any questions or comments about this advisory:

CVE-2023-23936

Impact

undici library does not protect host HTTP header from CRLF injection vulnerabilities.

Patches

This issue was patched in Undici v5.19.1.

Workarounds

Sanitize the headers.host string before passing to undici.

References

Reported at https://hackerone.com/reports/1820955.

Credits

Thank you to Zhipeng Zhang (@​timon8) for reporting this vulnerability.

CVE-2023-24807

Impact

The Headers.set() and Headers.append() methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the headerValueNormalize() utility function.

Patches

This vulnerability was patched in v5.19.1.

Workarounds

There is no workaround. Please update to an unaffected version.

References

Credits

Carter Snook reported this vulnerability.

CVE-2025-47279

Impact

Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.

Patches

This has been patched in https://github.com/nodejs/undici/pull/4088.

Workarounds

If a webhook fails, avoid keep calling it repeatedly.

References

Reported as: https://github.com/nodejs/undici/issues/3895

CVE-2026-22036

Impact

The fetch() API supports chained HTTP encoding algorithms for response content according to RFC 9110 (e.g., Content-Encoding: gzip, br). This is also supported by the undici decompress interceptor.

However, the number of links in the decompression chain is unbounded and the default maxHeaderSize allows a malicious server to insert thousands compression steps leading to high CPU usage and excessive memory allocation.

Patches

Upgrade to 7.18.2 or 6.23.0.

Workarounds

It is possible to apply an undici interceptor and filter long Content-Encoding sequences manually.

References


Release Notes

nodejs/undici (undici@>=4.5.0 <5.28.5)

v6.23.0

Compare Source

Full Changelog: nodejs/undici@v6.22.0...v6.23.0

v6.22.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.21.3...v6.22.0

v6.21.3

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.21.2...v6.21.3

v6.21.2

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.21.1...v6.21.2

v6.21.1

Compare Source

⚠️ Security Release ⚠️

Fixes CVE CVE-2025-22150 GHSA-c76h-2ccp-4975 (embargoed until 22-01-2025).

What's Changed

Full Changelog: nodejs/undici@v6.21.0...v6.21.1

v6.21.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.20.1...v6.21.0

v6.20.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.20.0...v6.20.1

v6.20.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.19.8...v6.20.0

v6.19.8

Compare Source

Full Changelog: nodejs/undici@v6.19.7...v6.19.8

v6.19.7

Compare Source

Full Changelog: nodejs/undici@v6.19.6...v6.19.7

v6.19.6

Compare Source

Full Changelog: nodejs/undici@v6.19.5...v6.19.6

v6.19.5

Compare Source

Full Changelog: nodejs/undici@v6.19.4...v6.19.5

v6.19.4

Compare Source

Full Changelog: nodejs/undici@v6.19.3...v6.19.4

v6.19.3

Compare Source

Full Changelog: nodejs/undici@v6.19.2...v6.19.3

v6.19.2

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.19.1...v6.19.2

v6.19.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.19.0...v6.19.1

v6.19.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.18.2...v6.19.0

v6.18.2

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.18.1...v6.18.2

v6.18.1

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.18.0...v6.18.1

v6.18.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.17.0...v6.18.0

v6.17.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.16.1...v6.17.0

v6.16.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.16.0...v6.16.1

v6.16.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.15.0...v6.16.0

v6.15.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.14.1...v6.15.0

v6.14.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.14.0...v6.14.1

v6.14.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.13.0...v6.14.0

v6.13.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.12.0...v6.13.0

v6.12.0

Compare Source

What's Changed


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from Dougley as a code owner September 28, 2025 17:26
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 9490c00 to 8929e9f Compare October 5, 2025 21:33
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Oct 5, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch 2 times, most recently from 8a9ef0a to 02483e4 Compare October 6, 2025 04:47
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Oct 6, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 02483e4 to 61e11ac Compare October 9, 2025 13:12
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Oct 9, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 61e11ac to 804fb65 Compare October 9, 2025 17:47
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Oct 9, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 804fb65 to 61ac65e Compare October 21, 2025 01:54
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Oct 21, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 61ac65e to af35810 Compare October 21, 2025 05:11
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Oct 21, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from af35810 to 3191d9d Compare October 22, 2025 12:04
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Oct 22, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 3191d9d to 6d48b72 Compare October 22, 2025 19:40
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Oct 22, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 6d48b72 to aa0c45b Compare November 1, 2025 12:45
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Nov 1, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from aa0c45b to 45ce932 Compare November 1, 2025 17:11
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Nov 1, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 45ce932 to f6f9dff Compare November 10, 2025 20:36
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Nov 10, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from f6f9dff to 4813047 Compare November 11, 2025 04:53
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Nov 11, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Nov 18, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 4813047 to f3791fa Compare November 18, 2025 19:55
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Nov 19, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from d6cf059 to c366395 Compare December 31, 2025 14:58
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Dec 31, 2025
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from c366395 to 6ce74e7 Compare December 31, 2025 20:58
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Dec 31, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Jan 5, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch 2 times, most recently from d5d0575 to 43b483f Compare January 5, 2026 17:40
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Jan 5, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 43b483f to 1729eca Compare January 5, 2026 18:03
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Jan 5, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 1729eca to 204a343 Compare January 5, 2026 21:05
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Jan 5, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 204a343 to 1444fb9 Compare January 8, 2026 16:41
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Jan 8, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 1444fb9 to 193db71 Compare January 8, 2026 21:51
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Jan 8, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch 2 times, most recently from f1d05e7 to f003460 Compare January 19, 2026 16:02
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Jan 19, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from f003460 to 9a0f293 Compare January 19, 2026 17:40
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Jan 19, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 9a0f293 to e2a57e4 Compare January 23, 2026 19:43
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Jan 23, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from e2a57e4 to 6585ae0 Compare January 23, 2026 22:51
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Jan 23, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 6585ae0 to 2b48dff Compare February 2, 2026 18:16
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] Feb 2, 2026
@renovate renovate bot force-pushed the renovate/npm-undici>=4.5.0-<5.28.5-vulnerability branch from 2b48dff to 0688631 Compare February 2, 2026 23:01
@renovate renovate bot changed the title chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to >=5.29.0 [security] chore(deps): update dependency undici@&gt;&#x3d;4.5.0 &lt;5.28.5 to v6 [security] Feb 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants