undici, Denial of Service via orphaned RetryHandler response body, CVE: Not Provided (Moderate) -DC-Sep2026-2629

Listen to this Post

The vulnerability affects undici’s RetryHandler.

RetryHandler can leave a response body pending indefinitely.

When a retried request receives a non-retryable response after a truncated one, the original response.body held by the application is never settled.

Reads such as response.body.text() hang.

The bodyTimeout does not fire in this state.

A malicious server can repeat this behavior.

Repeated attempts accumulate pending promises.

Repeated attempts accumulate pending streams.

This accumulation can lead to denial of service.

The issue is in undici versions >= 7.11.0, < 7.29.1.
The issue is also in >= 8.0.0, < 8.10.2.

Patched versions are 7.29.1 and 8.10.2.

Severity is Moderate.

Published Sep 4, 2026.

Updated Sep 29, 2026.

GitHub Reviewed.

Package is nodejs/undici.

The advisory is from the National Vulnerability Database.

Published to the GitHub Advisory Database.

Reviewed.

Last updated.

The root cause is an orphaned RetryHandler response body.

The application holds response.body.

The body is never settled.

bodyTimeout does not fire.

A malicious server can trigger a non-retryable response after a truncated response.

The server can repeat this.

Pending promises grow.

Pending streams grow.

Denial of service occurs.

Workaround: impose an independent request deadline.

Workaround: destroy the response body when it expires.

bodyTimeout alone does not prevent this.

No CVE ID is provided in the .

DailyCVE Form:

Platform: undici Node.js
Version: 7.11.0–7.29.1 8.0.0–8.10.2
Vulnerability: RetryHandler body DoS
Severity: Moderate
date: Sep 4, 2026

Prediction: Sep 29, 2026

What Undercode Say:

Analytics

npm ls undici
npm audit --audit-level=moderate
node -e "console.log(require('undici/package.json').version)"
const { request, RetryHandler, Agent } = require('undici');
const agent = new Agent({
factory: (origin, opts) => new RetryHandler(opts)
});
const res = await request('http://malicious.example', {
dispatcher: agent,
bodyTimeout: 1000
});
await res.body.text();

Exploit: (Educational Purposes!)

const { request, RetryHandler, Agent } = require('undici');
const agent = new Agent({
factory: (origin, opts) => new RetryHandler(opts)
});
const res = await request('http://malicious.example', {
dispatcher: agent,
bodyTimeout: 1000
});
await res.body.text();

Protection: from this CVE

const controller = new AbortController();
const timer = setTimeout(() => controller.abort(), 5000);
try {
const res = await request(url, {
signal: controller.signal,
bodyTimeout: 1000
});
await res.body.text();
} finally {
clearTimeout(timer);
}
const res = await request(url, { bodyTimeout: 1000 });
setTimeout(() => res.body.destroy(), 5000);

Impact:

Denial of service via pending promises and streams.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top