CVE-2026-18149: Unresolved Response Body Hang in Undici RetryHandler
Vulnerability ID: CVE-2026-18149
CVSS Score: 5.9
Published: 2026-09-29
A resource management vulnerability in the Undici HTTP client (CWE-772) occurs when the retry interceptor receives a partial body payload followed by a non-retryable response error on a subsequent connection attempt, resulting in orphaned streams and potential Denial of Service (DoS).
TL;DR
An unmitigated resource leak in undici's RetryHandler causes application-level hangs and Denial of Service when handling aborted responses followed by non-retryable errors.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-772
- Attack Vector: Network (AV:N)
- CVSS Score: 5.9 (Medium)
- EPSS Score: 0.0036 (0.36%)
- Impact: Denial of Service (DoS)
- Exploit Status: Proof-of-Concept (PoC) available
- KEV Status: Not listed
Affected Systems
- Node.js applications using Undici HTTP client within 7.x and 8.x version branches.
-
undici: >= 7.11.0 < 7.29.1 (Fixed in:
7.29.1) -
undici: >= 8.0.0 < 8.10.2 (Fixed in:
8.10.2)
Code Analysis
Commit: e905b5b
Fix retry handler holding response body indefinitely on unretryable status errors.
Commit: 3c67265
Ensure error propagation to original controllers when retried requests fail directly.
Mitigation Strategies
- Disable retry middleware configurations when interacting with untrusted or external APIs.
- Implement client-side request timeout wrappers using AbortSignal to prevent indefinite stream hangs.
- Enforce API gateways or reverse proxies to normalize and sanitize broken TCP connections before they reach application-level clients.
Remediation Steps:
- Identify all projects and packages containing dependencies on Undici via
npm ls undici. - Upgrade Undici to version 7.29.1 or 8.10.2 depending on the respective release branch.
- Validate the patch behavior by deploying the reproduction test suite in target environments.
References
- GitHub Security Advisory GHSA-pmjh-fq2x-6v4x
- NVD CVE-2026-18149 Details
- CVE.org CVE-2026-18149
- OpenJS Foundation Security Advisories
Read the full report for CVE-2026-18149 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)