undici vulnerable to Denial of Service via orphaned RetryHandler response body
Package
Affected versions
>= 7.11.0, < 7.29.1
>= 8.0.0, < 8.10.2
Patched versions
7.29.1
8.10.2
Description
Published by the National Vulnerability Database
Sep 4, 2026
Published to the GitHub Advisory Database
Sep 29, 2026
Reviewed
Sep 29, 2026
Last updated
Sep 29, 2026
Impact
undici's
RetryHandlercan leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the originalresponse.bodyheld by the application is never settled, so reads such asresponse.body.text()hang andbodyTimeoutdoes not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.Patches
Patched in undici v7.29.1 and v8.10.2.
Workarounds
Impose an independent request deadline and destroy the response body when it expires.
bodyTimeoutalone does not prevent this.References