chore(deps): update dependency undici to v6.28.1 [security] - #1874
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedAuto reviews are limited based on label configuration. 🏷️ Required labels (at least one) (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository: Zoo-Code-Org/Zoo-Code/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Review statusThis PR was opened by an automated account. A human maintainer must verify the change intent, provenance, and validation before merging. Current step: Awaiting fresh human maintainer or CODEOWNER approval. Review-state labels are managed by this workflow; do not edit them manually. |
This PR contains the following updates:
6.28.0→6.28.1undici vulnerable to downstream response splitting via retry interceptor
CVE-2026-18540 / GHSA-r53p-7pc4-xj5r
More information
Details
Impact
Undici's
interceptors.retry()can resume a request after a partial response and append the resumed bytes to an already partially delivered body, while the application still receives the original response's status and headers. When that response carried aContent-Length, the application can receive a longer body. Applications that forward Undici's status, headers, and body downstream without recalculating framing, for example proxy or gateway applications, may emit a response whose body exceeds the forwardedContent-Length, and the excess bytes can be read as the start of a subsequent HTTP response (downstream response splitting or desynchronization).For example, a
404 Not FoundwithContent-Length: 2that sends one byte then closes can be resumed with an open-endedRangerequest, and the resumed206 Partial Contentbytes are appended, so the application receives more than two body bytes while still seeingContent-Length: 2. The bug requiresinterceptors.retry()enabled, an attacker-controlled or faulty upstream, and a downstream forwarder that does not recalculateContent-Length.Patches
Patched in undici v6.28.1, v7.29.1, and v8.10.2. Upgrade to one of these or later.
Workarounds
interceptors.retry()for untrusted upstreams, or setmaxRetries: 0.Content-Lengthbefore forwarding a response body assembled by Undici.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nodejs/undici (undici)
v6.28.1Compare Source
High severity
TypeErrorthat could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 2af0faf8.Medium severity
Low severity
Content-Rangeagainst the original response framing before resuming. Fixed by ce31bc82.What's Changed
Full Changelog: nodejs/undici@v6.28.0...v6.28.1
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.