Medium · 4.8 Node.js & npm GHSA-2jfj-6hjv-fm6j CVE-2026-84933 GHSA-3wwx-pv8p-q78v CVE-2026-85024
undici: five vulnerabilities allow cookie leakage and multiple denial-of-service conditions
Five separate vulnerabilities in the undici HTTP/WebSocket client for Node.js allow cross-user cookie disclosure via shared caching and multiple ways to crash a Node.js process through malicious or compromised servers. All are fixed in undici 7.29.1 and 8.10.2.
AI summary
GitHub's advisory database has published five vulnerabilities affecting undici, the HTTP/1.1 client that underlies Node.js's built-in fetch and WebSocket implementations. One issue allows a shared HTTP cache to leak one user's cookies to another user. The remaining four are denial-of-service issues that let a malicious or compromised remote server crash the Node.js process hosting the client. All five are fixed in undici 7.29.1 and 8.10.2; one fix is also available in 6.28.1.
What happened
Five vulnerabilities were disclosed in undici: 1. CVE-2026-84933 (GHSA-2jfj-6hjv-fm6j): the `interceptors.cache()` feature does not strip `Set-Cookie` headers before storing a cacheable response in shared-cache mode. A cookie set for one user can be re-served from the cache to a different, later caller using the same cache key. 2. CVE-2026-85024 (GHSA-3wwx-pv8p-q78v): the WebSocket client's permessage-deflate decompression path removes its internal error listener when a size limit is hit but leaves the decompression stream running. A subsequent decompression error then triggers an unhandled error event that crashes the Node.js process. 3. CVE-2026-84890 (GHSA-3xpg-4rpp-hhhm): the `interceptors.decompress()` feature caps the number of decompression layers but does not bound total decompressed output size, allowing a compression bomb to exhaust process memory. 4. CVE-2026-18149 (GHSA-pmjh-fq2x-6v4x): `RetryHandler` can leave a response body pending indefinitely after a retried request receives a non-retryable response following a truncated one, so reads on that body hang and `bodyTimeout` does not fire. 5. CVE-2026-85014 (GHSA-rx4f-c7p8-82vq): `WebSocketStream` calls `abort()` on a locked writable stream during an unclean connection close; the resulting promise rejection is not handled, producing an unhandled rejection that terminates the process.
Technical cause
The cookie-disclosure issue stems from the cache interceptor not implementing the RFC 6265 section 7.2 requirement that a shared cache must not store `Set-Cookie` headers. The four denial-of-service issues share a common pattern: internal stream or promise error paths are not properly handled, so errors that should be contained within undici's internals instead surface as unhandled `error` or `unhandledRejection` events, which Node.js treats as fatal by default. In the decompression-bomb case, the root cause is instead a missing resource limit rather than an unhandled error.
Why it matters
undici is bundled with Node.js and used directly or indirectly by a very large number of server-side JavaScript applications, so these issues have broad reach. The cookie-disclosure issue (CVSS 6.5) can expose session or authentication cookies belonging to one user to another caller when an application uses undici's shared cache against an untrusted or multi-user upstream. The four denial-of-service issues (each CVSS 5.9) allow a single malicious or compromised remote server to crash the entire Node.js process hosting the client — in several cases with just one connection or request, and in the WebSocket decompression case the attack can be repeated on reconnect to cause a crash loop.
Who is affected
Applications using undici as an HTTP client or using Node.js's bundled `globalThis.WebSocket` (which is built on undici) are potentially affected, depending on which feature is used: - Shared-cache cookie disclosure: applications using `interceptors.cache()` with `type: 'shared'` (the default) against untrusted or multi-user upstreams. Private caches (`type: 'private'`) are not affected. - WebSocket permessage-deflate crash: applications using the undici WebSocket client or Node.js's bundled WebSocket that can connect to an attacker-controlled or compromised WebSocket endpoint. - Decompression bomb: applications using `interceptors.decompress()` against untrusted or faulty upstreams. - RetryHandler DoS: applications using `RetryHandler` against a server that can send truncated then non-retryable responses. - WebSocketStream crash: applications using the `WebSocketStream` API and writing through a writer, described as the standard way to write to it.
Affected versions
Affected ranges differ per issue: - CVE-2026-84933 (cookie disclosure): undici >= 7.0.0, < 7.29.1 and >= 8.0.0, < 8.10.2. - CVE-2026-85024 (permessage-deflate crash): undici >= 6.25.0, < 6.28.1; >= 7.28.0, < 7.29.1; and >= 8.1.0, < 8.10.2. - CVE-2026-84890 (decompression bomb): undici >= 7.15.0, < 7.29.1 and >= 8.0.0, < 8.10.2. - CVE-2026-18149 (RetryHandler DoS): undici >= 7.11.0, < 7.29.1 and >= 8.0.0, < 8.10.2. - CVE-2026-85014 (WebSocketStream crash): all releases from undici 7.0.0 up to, but not including, 7.29.1, and >= 8.0.0, < 8.10.2 (WebSocketStream was introduced in 7.0.0).
Fixes and mitigation
All five issues are fixed in undici 7.29.1 and 8.10.2. The permessage-deflate crash (CVE-2026-85024) is additionally fixed in 6.28.1 for applications on the 6.x line. Per-issue mitigations where no upgrade is yet applied: - Cookie disclosure: use a private cache (`type: 'private'`) for per-user responses, avoid caching responses that set cookies, or strip `Set-Cookie` from responses before caching. - Decompression bomb: avoid `interceptors.decompress()` against untrusted upstreams, or apply a custom interceptor enforcing a decompressed size limit; after upgrading, set a conservative `maxSize` option (default 64 MiB) on the interceptor. - RetryHandler DoS: impose an independent request deadline and destroy the response body when it expires, since `bodyTimeout` alone does not prevent this. - Permessage-deflate crash and WebSocketStream crash: no workaround is available other than upgrading.
Recommended action
Upgrade undici to 8.10.2, or to 7.29.1 if remaining on the 7.x line. Applications still on the 6.x line should upgrade to at least 6.28.1 to address the permessage-deflate crash, though note that the other four issues are not listed as fixed on the 6.x line in the available information. Review usage of `interceptors.cache()`, `interceptors.decompress()`, `RetryHandler`, and WebSocket/WebSocketStream APIs to confirm whether the applicable workarounds are needed in the interim.
PatchBriefing score
4.8 / 10 · Medium
Official CVSS: 6.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Why this score
The cookie-disclosure issue (CVE-2026-84933) has a CVSS base score of 6.5, driven by a confidentiality impact (cookies of one user exposed to another) combined with high attack complexity, no privileges or user interaction required, and network attack vector. The four denial-of-service issues each carry a CVSS base score of 5.9, reflecting a high availability impact (process crash), high attack complexity, network vector, and no privileges or user interaction required. None of the five issues is listed as known exploited, has a public exploit, or has an assigned EPSS score (two items include EPSS percentages below 0.5%, indicating low observed exploitation likelihood). Fixes are available for all issues, which is factored into the PatchBriefing scores (4.5–4.8) for each advisory.
Affected versions
- undici >= 8.0.0, < 8.10.2
- vulnerable
- ≥ 7.29.1
- patched
- ≥ 8.10.2
- patched
- undici >= 8.1.0, < 8.10.2
- vulnerable
- ≥ 6.28.1
- patched
- ≥ 7.29.1
- patched
- ≥ 8.10.2
- patched
- undici >= 8.0.0, < 8.10.2
- vulnerable
- ≥ 7.29.1
- patched
- ≥ 8.10.2
- patched
- undici >= 8.0.0, < 8.10.2
- vulnerable
- ≥ 7.29.1
- patched
- ≥ 8.10.2
- patched
- undici >= 8.0.0, < 8.10.2
- vulnerable
- ≥ 7.29.1
- patched
- ≥ 8.10.2
- patched
Reported fixes
All five issues are fixed in undici 7.29.1 and 8.10.2. The permessage-deflate crash (CVE-2026-85024) is additionally fixed in 6.28.1 for applications on the 6.x line. Per-issue mitigations where no upgrade is yet applied: - Cookie disclosure: use a private cache (`type: 'private'`) for per-user responses, avoid caching responses that set cookies, or strip `Set-Cookie` from responses before caching. - Decompression bomb: avoid `interceptors.decompress()` against untrusted upstreams, or apply a custom interceptor enforcing a decompressed size limit; after upgrading, set a conservative `maxSize` option (default 64 MiB) on the interceptor. - RetryHandler DoS: impose an independent request deadline and destroy the response body when it expires, since `bodyTimeout` alone does not prevent this. - Permessage-deflate crash and WebSocketStream crash: no workaround is available other than upgrading.
How this was built
5 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email