Executive brief
Undici is a popular HTTP client library for Node.js used by many JavaScript applications. When the deduplication feature is enabled, a flaw allows attackers to cause memory exhaustion and crash the application by sending large responses paired with concurrent identical requests. This can lead to service unavailability and potential application downtime.
Technical details
The vulnerability is an uncontrolled resource consumption issue (CWE-770) in Undici's DeduplicationHandler interceptor. When interceptors.deduplicate() is enabled, response bodies are accumulated in memory rather than streamed to downstream handlers, allowing attackers to trigger out-of-memory (OOM) conditions through large or chunked responses combined with concurrent identical requests. The attack requires no authentication or user interaction and is triggered via network requests to an attacker-controlled or untrusted upstream endpoint. The vulnerability affects versions 7.17.0 through 7.23.x and is fixed in version 7.24.0 and later by implementing response streaming instead of full-body accumulation.
Affected products
- Node.js Undici 7.17.0 to 7.23.x
Timeline
- 2026-03-12: disclosed
- 2026-03-13: patched: Patch released in version 7.24.0