DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-18149: CVE-2026-18149: Unresolved Response Body Hang in Undici RetryHandler

CVE-2026-18149: Unresolved Response Body Hang in Undici RetryHandler

Vulnerability ID: CVE-2026-18149
CVSS Score: 5.9
Published: 2026-09-29

A resource management vulnerability in the Undici HTTP client (CWE-772) occurs when the retry interceptor receives a partial body payload followed by a non-retryable response error on a subsequent connection attempt, resulting in orphaned streams and potential Denial of Service (DoS).

TL;DR

An unmitigated resource leak in undici's RetryHandler causes application-level hangs and Denial of Service when handling aborted responses followed by non-retryable errors.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-772
  • Attack Vector: Network (AV:N)
  • CVSS Score: 5.9 (Medium)
  • EPSS Score: 0.0036 (0.36%)
  • Impact: Denial of Service (DoS)
  • Exploit Status: Proof-of-Concept (PoC) available
  • KEV Status: Not listed

Affected Systems

  • Node.js applications using Undici HTTP client within 7.x and 8.x version branches.
  • undici: >= 7.11.0 < 7.29.1 (Fixed in: 7.29.1)
  • undici: >= 8.0.0 < 8.10.2 (Fixed in: 8.10.2)

Code Analysis

Commit: e905b5b

Fix retry handler holding response body indefinitely on unretryable status errors.

Commit: 3c67265

Ensure error propagation to original controllers when retried requests fail directly.

Mitigation Strategies

  • Disable retry middleware configurations when interacting with untrusted or external APIs.
  • Implement client-side request timeout wrappers using AbortSignal to prevent indefinite stream hangs.
  • Enforce API gateways or reverse proxies to normalize and sanitize broken TCP connections before they reach application-level clients.

Remediation Steps:

  1. Identify all projects and packages containing dependencies on Undici via npm ls undici.
  2. Upgrade Undici to version 7.29.1 or 8.10.2 depending on the respective release branch.
  3. Validate the patch behavior by deploying the reproduction test suite in target environments.

References


Read the full report for CVE-2026-18149 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)