This repository was archived by the owner on May 15, 2026. It is now read-only.
Update dependency undici to v6.24.0 [SECURITY] - #10739
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
2 times, most recently
from
January 23, 2026 17:38
0281951 to
0506d35
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
February 2, 2026 15:30
0506d35 to
fe1bff1
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
February 12, 2026 10:09
fe1bff1 to
8f87cc4
Compare
renovate
Bot
requested review from
daniel-lxs and
hannesrudolph
as code owners
February 12, 2026 10:09
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
3 times, most recently
from
February 17, 2026 19:33
d5aeb86 to
ef782ca
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
March 5, 2026 15:56
ef782ca to
3ce0052
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
2 times, most recently
from
March 14, 2026 06:39
8790d91 to
b29ed9b
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
March 30, 2026 21:44
c2c2a73 to
b29ed9b
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
March 30, 2026 21:44
b29ed9b to
c2c2a73
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
April 8, 2026 14:50
c2c2a73 to
8af5c60
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
April 27, 2026 23:52
d0fe0bf to
8af5c60
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
April 27, 2026 23:52
8af5c60 to
d0fe0bf
Compare
renovate
Bot
force-pushed
the
renovate/npm-undici-vulnerability
branch
from
May 12, 2026 02:48
d0fe0bf to
1f5d330
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.21.3→6.24.0Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client
CVE-2026-1528 / GHSA-f269-vfmq-vjvj
More information
Details
Impact
A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.
Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Workarounds
There are no workarounds.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Undici has an HTTP Request/Response Smuggling issue
CVE-2026-1525 / GHSA-2mjp-6q6p-2qxm
More information
Details
Impact
Undici allows duplicate HTTP
Content-Lengthheaders when they are provided in an array with case-variant names (e.g.,Content-Lengthandcontent-length). This produces malformed HTTP/1.1 requests with multiple conflictingContent-Lengthvalues on the wire.Who is impacted:
undici.request(),undici.Client, or similar low-level APIs with headers passed as flat arraysPotential consequences:
Content-Lengthheaders (400 Bad Request)Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Workarounds
If upgrading is not immediately possible:
Content-Lengthheaders (case-insensitive) are present before passing headers to undici{ 'content-length': '123' }) rather than an array, which naturally deduplicates by keySeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Undici has CRLF Injection in undici via
upgradeoptionCVE-2026-1527 / GHSA-4992-7rv2-5pvq
More information
Details
Impact
When an application passes user-controlled input to the
upgradeoption ofclient.request(), an attacker can inject CRLF sequences (\r\n) to:The vulnerability exists because undici writes the
upgradevalue directly to the socket without validating for invalid header characters:Patches
Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.
Workarounds
Sanitize the
upgradeoption string before passing to undici:Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodejs/undici (undici)
v6.24.0Compare Source
Undici v6.24.0 Security Release Notes (LTS)
This release backports fixes for security vulnerabilities affecting the v6 line.
Upgrade guidance
All users on v6 should upgrade to v6.24.0 or later.
Fixed advisories
GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 (Medium)
Inconsistent interpretation of HTTP requests (request/response smuggling class issue).
GHSA-f269-vfmq-vjvj / CVE-2026-1528 (High)
Malicious WebSocket 64-bit frame length handling could crash the client.
GHSA-4992-7rv2-5pvq / CVE-2026-1527 (Medium)
CRLF injection via the
upgradeoption.GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 (High)
Unhandled exception from invalid
server_max_window_bitsin WebSocket permessage-deflate negotiation.GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 (High)
Unbounded memory consumption in WebSocket permessage-deflate decompression.
Not applicable to v6
>= 7.17.0 < 7.24.0only.Affected and patched ranges (v6)
< 6.24.0, patched6.24.0>= 6.0.0 < 6.24.0, patched6.24.0< 6.24.0, patched6.24.0< 6.24.0, patched6.24.0< 6.24.0, patched6.24.0References
v6.23.0Compare Source
Full Changelog: nodejs/undici@v6.22.0...v6.23.0
v6.22.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v6.21.3...v6.22.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.