chore(deps): update dependency undici to v7.29.0#34
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
July 18, 2025 16:34
0800216 to
0f00bde
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
July 31, 2025 11:46
0f00bde to
587a3da
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
August 17, 2025 14:26
587a3da to
1959b32
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
August 22, 2025 17:10
1959b32 to
b01faef
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
September 9, 2025 17:40
b01faef to
6b2ae24
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
January 5, 2026 16:01
6b2ae24 to
3da96aa
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
January 6, 2026 14:03
3da96aa to
ba5191b
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
January 6, 2026 18:35
ba5191b to
e9ee1d8
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
January 21, 2026 14:04
e9ee1d8 to
957824f
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
January 24, 2026 18:06
957824f to
d5f3c27
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
January 27, 2026 22:29
d5f3c27 to
a427e0e
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
February 2, 2026 01:29
a427e0e to
501c2d6
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
February 6, 2026 13:12
501c2d6 to
70c0907
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
February 14, 2026 01:11
70c0907 to
d32059a
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
March 12, 2026 12:57
d32059a to
7328590
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
March 13, 2026 15:56
b378f8b to
7a17980
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
March 14, 2026 22:16
7a17980 to
d5be04a
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
March 16, 2026 09:25
d5be04a to
4b018a2
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
March 20, 2026 01:05
4b018a2 to
7da1798
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
March 25, 2026 18:10
7da1798 to
48d5475
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
April 1, 2026 13:30
48d5475 to
96eaa2a
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
April 12, 2026 21:44
96eaa2a to
d83106b
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
April 13, 2026 15:10
d83106b to
51cac48
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
May 25, 2026 17:00
51cac48 to
5a687fa
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
June 1, 2026 18:34
5a687fa to
373b1e3
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
June 4, 2026 08:54
373b1e3 to
26d9e8c
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
June 6, 2026 09:04
26d9e8c to
209db76
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
June 16, 2026 00:56
209db76 to
330a328
Compare
renovate
Bot
force-pushed
the
renovate/undici-7.x-lockfile
branch
from
July 24, 2026 13:41
330a328 to
b73ee94
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.10.0→7.29.0Release Notes
nodejs/undici (undici)
v7.29.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.28.0...v7.29.0
v7.28.0Compare Source
This release line addresses 7 security advisories, all shipped in v7.28.0.
The v7 line is not affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is
an 8.x-only regression.
Summary
8cb10f9804201f893805b8f885a24055d0574cc4d0574cc4ea8930cfHigh severity
WebSocket DoS via fragment count bypass — CVE-2026-12151
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix:
8cb10f98websocket: limit the number of fragments in a message (part of backporta027a4a0Backport WebSocket maxPayloadSize fixes to v7.x, #5423)A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service.
new WebSocket(...)orWebSocketStreamagainst untrusted endpoints.
TLS certificate validation bypass in SOCKS5 ProxyAgent — CVE-2026-9697
GHSA-vmh5-mc38-953g · CWE-295
Fix:
04201f89fix: honor requestTls when proxy is SOCKS5 (#5417)The
ProxyAgentsilently discarded therequestTlsoption when configured witha SOCKS5 proxy. TLS connections through the SOCKS5 tunnel ignored user-configured
parameters such as
ca,cert,key,rejectUnauthorized, andservername,falling back to the default Mozilla CA bundle. Applications relying on
certificate pinning to an internal CA were exposed to man-in-the-middle attacks.
ProxyAgent/Socks5ProxyAgentover SOCKS5 that rely onrequestTls.ProxyAgent, whererequestTlsfunctions correctly.Cross-origin request routing via SOCKS5 proxy pool reuse — CVE-2026-6734
GHSA-hm92-r4w5-c3mj · CWE-346
Fix:
3805b8f8fix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing (#5041)Socks5ProxyAgentreused a single connection pool across different originswithout verifying the pool's origin matched the requested origin. This could
route credentials and request data to unintended destinations, cause responses
from the wrong origin to be trusted, and enable HTTPS→HTTP downgrade.
Socks5ProxyAgentacross multiple origins(introduced in 7.23.0 via #4385).
Moderate severity
Cross-user information disclosure via shared cache whitespace bypass — CVE-2026-9678
GHSA-pr7r-676h-xcf6 · CWE-524
Fix:
85a24055fix(cache): trim qualified field namesThe cache interceptor mishandled responses with whitespace-padded
Cache-Controldirectives such asprivate=" authorization". In shared-cachemode this could cause authenticated data to be cached and served to other users.
Authorizationupstream and receive non-canonical qualified directives.caching authenticated responses, or add
Vary: Authorizationupstream.HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679
GHSA-p88m-4jfj-68fv · CWE-93
Fix:
d0574cc4fix(cookies): preserve values and parse SameSite strictlyparseSetCookieapplied percent-decoding to cookie values, turning encodedsequences like
%0D%0Aand%00into literal bytes, contrary to RFC 6265 §5.4and browser behavior. Applications forwarding parsed Set-Cookie values into
response headers were exposed to header injection, enabling session fixation,
open redirects, and cache poisoning. Introduced in 7.0.0 via
#3789.
NUL,
;, and=.Low severity
Set-Cookie SameSite attribute downgrade — CVE-2026-11525
GHSA-g8m3-5g58-fq7m · CWE-183
Fix:
d0574cc4fix(cookies): preserve values and parse SameSite strictlyThe cookie parser accepted
SameSitevalues containingStrict,Lax, orNoneas substrings rather than requiring exact matches per RFC 6265. Valueslike
SameSite=NoneOfYourBusinessparsed asNone, andSameSite=StrictLaxparsed as
Lax, silently weakening cookie security policies for apps thatforward parsed attributes.
HTTP response queue poisoning via keep-alive socket reuse — CVE-2026-6733
GHSA-35p6-xmwp-9g52 · CWE-367 (TOCTOU race condition)
Fix:
ea8930cffix: guard idle socket validation to skip fresh sockets, hardened by8e4046e4keep idle validation on native timers (#5402) and0fa80869keep idle validation on global timers (#5409)An attacker controlling an upstream HTTP/1.1 server could inject unsolicited
responses onto idle keep-alive sockets. On socket reuse, the injected response
was associated with a new request, delivering responses to the wrong requests.
keep-alive reuse.
keepAliveTimeout: 0on theClient or Pool.
Release contents & deliberate backports
v7.28.0 is a security-only release — every change in it is one of the fixes
above, backported to the v7.x maintenance line on purpose from the v8
development line:
#5423— backport of the WebSocketmaxPayloadSizefragment-count / cumulative-size limits (CVE-2026-12151).#5402ᔡ— backport of the idle-validation hardening (native + global timers) for the queue-poisoning fix (CVE-2026-6733).#5417—requestTlsover SOCKS5 fix (CVE-2026-9697).The cookie (
d0574cc4),cache (
85a24055) andqueue-poisoning core (
ea8930cf)fixes were applied directly to the v7.x branch. Full changelog:
v7.27.2...v7.28.0.Credits
Per-advisory credits (as recorded in each GHSA):
v7.27.2Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.27.1...v7.27.2
v7.27.1Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.27.0...v7.27.1
v7.27.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.26.0...v7.27.0
v7.26.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.25.0...v7.26.0
v7.25.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.8...v7.25.0
v7.24.8Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.7...v7.24.8
v7.24.7Compare Source
What's Changed
redirectionLimitReachedby @samuel871211 in #4933New Contributors
Full Changelog: nodejs/undici@v7.24.6...v7.24.7
v7.24.6Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.24.5...v7.24.6
v7.24.5Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.24.4...v7.24.5
v7.24.4Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.3...v7.24.4
v7.24.3Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.2...v7.24.3
v7.24.2Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.1...v7.24.2
v7.24.1Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.24.0...v7.24.1
v7.24.0Compare Source
Undici v7.24.0 Security Release Notes
This release addresses multiple security vulnerabilities in Undici.
Upgrade guidance
All users on v7 should upgrade to v7.24.0 or later.
Fixed advisories
GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 (Medium)
Inconsistent interpretation of HTTP requests (request/response smuggling class issue).
GHSA-f269-vfmq-vjvj / CVE-2026-1528 (High)
Malicious WebSocket 64-bit frame length handling could crash the client.
GHSA-phc3-fgpg-7m6h / CVE-2026-2581 (Medium)
Unbounded memory consumption in deduplication interceptor response buffering (DoS risk).
GHSA-4992-7rv2-5pvq / CVE-2026-1527 (Medium)
CRLF injection via the
upgradeoption.GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 (High)
Unhandled exception from invalid
server_max_window_bitsin WebSocket permessage-deflate negotiation.GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 (High)
Unbounded memory consumption in WebSocket permessage-deflate decompression.
Affected and patched ranges
7.0.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.0>= 7.17.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.07.0.0 < 7.24.0, patched7.24.0References
v7.23.0Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.22.0...v7.23.0
v7.22.0Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.21.0...v7.22.0
v7.21.0Compare Source
What's Changed
closemethod to WebSocketStream interface by @piotr-cz in #4802New Contributors
Full Changelog: nodejs/undici@v7.20.0...v7.21.0
v7.20.0Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.19.2...v7.20.0
v7.19.2Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.19.1...v7.19.2
v7.19.1Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.19.0...v7.19.1
v7.19.0Compare Source
What's Changed
New Contributors
Full Changelog: nodejs/undici@v7.18.2...v7.19.0
v7.18.2Compare Source
This fixes GHSA-g9mf-h72j-4rw9 and CVE-2026-22036.
What's Changed
Full Changelog: nodejs/undici@v7.18.1...v7.18.2
v7.18.1Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.18.0...v7.18.1
v7.18.0Compare Source
What's Changed
Full Changelog: nodejs/undici@v7.17.0...v7.18.0
v7.17.0Compare Source
What's Changed
'node:'prefix for requiring node built-ins by @Uzlopak in #4547statusinResponse.redirectby @gineika in #4591304 not modifiedreply upon revalidation did not update cache. by @daan944 in #4617Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.