Listen to this Post
The vulnerability affects undici’s RetryHandler.
RetryHandler can leave a response body pending indefinitely.
When a retried request receives a non-retryable response after a truncated one, the original response.body held by the application is never settled.
Reads such as response.body.text() hang.
The bodyTimeout does not fire in this state.
A malicious server can repeat this behavior.
Repeated attempts accumulate pending promises.
Repeated attempts accumulate pending streams.
This accumulation can lead to denial of service.
The issue is in undici versions >= 7.11.0, < 7.29.1.
The issue is also in >= 8.0.0, < 8.10.2.
Patched versions are 7.29.1 and 8.10.2.
Severity is Moderate.
Published Sep 4, 2026.
Updated Sep 29, 2026.
GitHub Reviewed.
Package is nodejs/undici.
The advisory is from the National Vulnerability Database.
Published to the GitHub Advisory Database.
Reviewed.
Last updated.
The root cause is an orphaned RetryHandler response body.
The application holds response.body.
The body is never settled.
bodyTimeout does not fire.
A malicious server can trigger a non-retryable response after a truncated response.
The server can repeat this.
Pending promises grow.
Pending streams grow.
Denial of service occurs.
Workaround: impose an independent request deadline.
Workaround: destroy the response body when it expires.
bodyTimeout alone does not prevent this.
No CVE ID is provided in the .
DailyCVE Form:
Platform: undici Node.js
Version: 7.11.0–7.29.1 8.0.0–8.10.2
Vulnerability: RetryHandler body DoS
Severity: Moderate
date: Sep 4, 2026
Prediction: Sep 29, 2026
What Undercode Say:
Analytics
npm ls undici
npm audit --audit-level=moderate
node -e "console.log(require('undici/package.json').version)"
const { request, RetryHandler, Agent } = require('undici');
const agent = new Agent({
factory: (origin, opts) => new RetryHandler(opts)
});
const res = await request('http://malicious.example', {
dispatcher: agent,
bodyTimeout: 1000
});
await res.body.text();
Exploit: (Educational Purposes!)
const { request, RetryHandler, Agent } = require('undici');
const agent = new Agent({
factory: (origin, opts) => new RetryHandler(opts)
});
const res = await request('http://malicious.example', {
dispatcher: agent,
bodyTimeout: 1000
});
await res.body.text();
Protection: from this CVE
const controller = new AbortController();
const timer = setTimeout(() => controller.abort(), 5000);
try {
const res = await request(url, {
signal: controller.signal,
bodyTimeout: 1000
});
await res.body.text();
} finally {
clearTimeout(timer);
}
const res = await request(url, { bodyTimeout: 1000 });
setTimeout(() => res.body.destroy(), 5000);
Impact:
Denial of service via pending promises and streams.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

