Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.4 Node.js & npm GHSA-rfgv-xxqx-mfg5 CVE-2026-19534 GHSA-w293-vg96-wgc3 CVE-2026-84961

Three undici Vulnerabilities Patched: DoS, TLS Bypass, and Cache Poisoning

Three separate vulnerabilities in the undici HTTP/WebSocket client for Node.js have been fixed: a remote denial-of-service via WebSocket subprotocol handling, a TLS certificate validation bypass in BalancedPool, and a cross-origin cache poisoning issue in interceptors. Upgrading to the patched releases is recommended.

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

The undici library, the HTTP/1.1 client built into Node.js and widely used as a standalone npm package, has received three separate security advisories. Each affects a distinct part of the library — the WebSocket client, the BalancedPool connection pooling mechanism, and the caching/deduplication interceptors — and each has an independent fix. None of the three are reported as actively exploited or as having public exploit code. This briefing covers all three together because they were published simultaneously and share the same affected package.

Three distinct issues in undici

GitHub Advisory Database published three undici advisories on the same day. CVE-2026-19534 (GHSA-rfgv-xxqx-mfg5) describes a denial-of-service condition in the WebSocket client: an uncaught exception is thrown when a server responds with a WebSocket subprotocol the client never requested, crashing the Node.js process. CVE-2026-84961 (GHSA-w293-vg96-wgc3) describes a TLS certificate validation bypass specific to BalancedPool, where a custom checkServerIdentity callback or connector function is silently dropped before reaching the TLS layer. CVE-2026-85152 (GHSA-vp8m-p9jh-q5pm) describes a cross-origin cache poisoning issue affecting the cache() and deduplicate() interceptors when their state is shared across multiple origins.

Root causes

The WebSocket DoS (CVE-2026-19534) occurs because the opening handshake code throws a TypeError inside a queueMicrotask callback with no surrounding try/catch, so the exception is uncaught and terminates the process; per RFC 6455, an unrequested subprotocol should fail the connection, not crash it. The TLS bypass (CVE-2026-84961) stems from BalancedPool passing constructor options through a JSON-based deep clone (JSON.parse(JSON.stringify(...))) before forwarding them to each per-upstream Pool; because JSON cannot represent functions, a supplied checkServerIdentity callback or custom connector is silently dropped, so Node's default certificate checks apply instead of the caller's stricter logic. Client, Pool, Agent, and RoundRobinPool destructure connect/tls options before the clone and are not affected. The cache poisoning issue (CVE-2026-85152) arises because cache and deduplication keys are built without the actual destination origin when a dispatcher lacks a single authoritative origin or a request supplies its own origin; if a cache store or interceptor instance is shared across origins, requests to different origins can be keyed together. Agent is not affected because its dispatch options include the request origin.

Why these matter

The WebSocket DoS (CVSS 7.5) can be triggered remotely and without authentication by any attacker-controlled or compromised WebSocket server, or by a machine-in-the-middle on a plaintext ws:// connection, and affects the default new WebSocket(url) usage with no workaround other than upgrading. The BalancedPool TLS bypass (CVSS 7.4) can cause a certificate that a custom checkServerIdentity was written to reject to be silently accepted, undermining intended TLS verification for applications using BalancedPool with custom connect/tls options. The cache poisoning issue (CVSS 7.4) allows an attacker who controls one origin's responses to have that response served for requests to a different, trusted origin, including scenarios such as JWKS cache poisoning where a token signed with an attacker-held key could be accepted as belonging to a trusted issuer.

Who is affected

All applications using undici's default WebSocket client (new WebSocket(url)) are potentially affected by the DoS issue. Only applications that use BalancedPool specifically, with a function-valued connect or tls option such as a custom checkServerIdentity or connector, are affected by the TLS bypass. Only applications that share interceptors.cache() or interceptors.deduplicate() state across more than one origin are affected by the cache poisoning issue; a plain Agent is not affected by either the TLS bypass or the cache poisoning issue.

Affected versions

WebSocket DoS (CVE-2026-19534): undici versions from 6.7.0 up to but not including 6.28.1, from 7.0.0 up to but not including 7.29.1, and from 8.0.0 up to but not including 8.10.2. TLS bypass (CVE-2026-84961): undici versions from 7.24.1 up to but not including 7.29.1, and from 8.0.0 up to but not including 8.10.2. Cache poisoning (CVE-2026-85152): undici versions from 8.10.0 up to but not including 8.10.2, specifically versions 8.10.0 and 8.10.1.

Fixes and mitigations

For the WebSocket DoS, upgrade to undici 6.28.1, 7.29.1, or 8.10.2; no workaround is available other than upgrading. For the BalancedPool TLS bypass, upgrade to 7.29.1 or 8.10.2, which preserve the connect and tls options outside the JSON clone; until upgraded, use Client, Pool, or Agent instead of BalancedPool for connections relying on a custom checkServerIdentity or connector. For the cache poisoning issue, upgrade to 8.10.2; until upgraded, use a separate cache store and a separate interceptor instance for each origin rather than sharing them across origins.

Recommended action

Site owners and developers using undici should upgrade to the fixed release in their major version line (6.28.1, 7.29.1, or 8.10.2, depending on which branch is in use) as soon as practical. Review any use of BalancedPool with custom TLS verification and any sharing of cache or deduplication interceptor state across origins, and apply the documented workarounds if an immediate upgrade is not possible.

PatchBriefing score

5.4 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

Each advisory carries its own CVSS score and PatchBriefing score. The WebSocket DoS has a CVSS base score of 7.5 and a PatchBriefing score of 5.4, reflecting that it is remotely triggerable without authentication or user interaction and affects a widely used package, but is not known to be exploited and has no public exploit code or EPSS data. The BalancedPool TLS bypass and the cache poisoning issue each have a CVSS base score of 7.4 and a PatchBriefing score of 5.3, for similar reasons: both are unauthenticated and require no user interaction, affect a high-popularity package, but are not known to be actively exploited, have no public exploit code, and have low EPSS likelihood scores reported in the underlying claims. None of the three are listed as known exploited or associated with ransomware activity.

Affected versions

undici >= 8.0.0, < 8.10.2
vulnerable
≥ 6.28.1
patched
≥ 7.29.1
patched
≥ 8.10.2
patched
undici >= 8.0.0, < 8.10.2
vulnerable
≥ 7.29.1
patched
≥ 8.10.2
patched
undici >= 8.10.0, < 8.10.2
vulnerable
≥ 8.10.2
patched

Reported fixes

For the WebSocket DoS, upgrade to undici 6.28.1, 7.29.1, or 8.10.2; no workaround is available other than upgrading. For the BalancedPool TLS bypass, upgrade to 7.29.1 or 8.10.2, which preserve the connect and tls options outside the JSON clone; until upgraded, use Client, Pool, or Agent instead of BalancedPool for connections relying on a custom checkServerIdentity or connector. For the cache poisoning issue, upgrade to 8.10.2; until upgraded, use a separate cache store and a separate interceptor instance for each origin rather than sharing them across origins.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • GitHub Advisory Database database
  • GitHub Advisory Database database
Unified report
Three undici Vulnerabilities Patched: DoS, TLS Bypass, and Cache Poisoning
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email