Overview
About vulnerability
Impact
Undici’s interceptors.retry() can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. Applications that use interceptors.retry() and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale Content-Length header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata.
A malicious or faulty upstream can respond to a range request with a 206 Partial Content response such as:
Content-Range: bytes 0-99/300
Content-Length: 300
and then send only 99 bytes before closing the socket. interceptors.retry() can then retry with Range: bytes=99-99, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain Content-Length: 300 from the first response.
The bug requires interceptors.retry() to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate Content-Length.
Patches
Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later.
Workarounds
- Disable
interceptors.retry()for untrusted upstreams. - Remove or recalculate
Content-Lengthbefore forwarding a response body assembled or transformed by Undici.
Details
- Affected product:
- AngularJS , Node.js , Protocol Buffers , React , Vue , api-extractor-model , astro , babel-loader , browser-sync , chrome-launcher , chromium-edge-launcher , cli , css-loader , css-minimizer-webpack-plugin , definitelytyped , del , dev-middleware , engine.io , esbuild-loader , extract-css-chunks-webpack-plugin , facebook/jest , facebook/metro , file-loader , file-system-cache , fork-ts-checker-webpack-plugin , friendly-errors-webpack-plugin , globby , got , happy-dom , hard-source-webpack-plugin , html-webpack-plugin , http-proxy-middleware , inquirer-external-editor , inquirer.js , jest , karma , karma-jasmine , karma-junit-reporter , karma-requirejs , metro , mini-css-extract-plugin , minimizer-webpack-plugin , mongodb , mongodb-connection-string-url , mongoose , nguniversal , nuxt , parse5 , plugins , postcss-loader , pretty-format , remix , rollup , rollup-plugin-node-resolve , rollup-plugin-sourcemaps , rules_nodejs , rushstack , selfsigned , socket.io , sort-package-json , storybook , strong-error-handler , style-resources-loader , thread-loader , time-fix-plugin , ts-command-line , undici , url-loader , vanilla-extract , vite , vite-node , webpack , webpack-dev-middleware , webpack-dev-server , webpackbar , worker-loader , xdm
- Affected packages:
- mongodb-connection-string-url @ 2.6.0 (+834 more)