PT-2026-86206 · Npm · Undici
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
undici versions 7.15.0 through 7.29.0
undici versions 8.0.0 through 8.10.1
Description
The decompress interceptor decompresses response bodies based on the untrusted
Content-Encoding header. Although the number of encoding layers is capped, the total decompressed output size is unbounded and lacks a configuration limit. A malicious upstream server can send a compression bomb—a small compressed payload that expands to hundreds of megabytes or more in client memory—leading to asymmetric resource consumption that can exhaust memory and crash the process, resulting in a Denial of Service (DoS).Recommendations
Update undici versions 7.15.0 through 7.29.0 to version 7.29.1.
Update undici versions 8.0.0 through 8.10.1 to version 8.10.2.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undici