Junglewise Threat Intelligence

CVE-2026-2581: Undici unbounded memory consumption in DeduplicationHandler

CVE-2026-2581 · Severity: low · CVSS 3.1 · Published 2026-03-13

Technologies: undici (npm). Vendors: npm.

Executive brief

Undici is a popular HTTP client library for Node.js used by many JavaScript applications. When the deduplication feature is enabled, a flaw allows attackers to cause memory exhaustion and crash the application by sending large responses paired with concurrent identical requests. This can lead to service unavailability and potential application downtime.

Technical details

The vulnerability is an uncontrolled resource consumption issue (CWE-770) in Undici's DeduplicationHandler interceptor. When interceptors.deduplicate() is enabled, response bodies are accumulated in memory rather than streamed to downstream handlers, allowing attackers to trigger out-of-memory (OOM) conditions through large or chunked responses combined with concurrent identical requests. The attack requires no authentication or user interaction and is triggered via network requests to an attacker-controlled or untrusted upstream endpoint. The vulnerability affects versions 7.17.0 through 7.23.x and is fixed in version 7.24.0 and later by implementing response streaming instead of full-body accumulation.

Affected products

  • Node.js Undici 7.17.0 to 7.23.x

Timeline

  • 2026-03-12: disclosed
  • 2026-03-13: patched: Patch released in version 7.24.0

References

Related threats