Description
undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the request. If the retry returns a non-retryable status such as 400, the handler forwards that new response downstream and replaces its internal response stream, but the original response body that the application still holds is never ended or destroyed. As a result calls that read that body never settle, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker-controlled server can trigger this with two short responses without keeping a connection open, and repeated requests accumulate pending promises and streams that can exhaust application concurrency or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.
Published: 2026-09-04
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

The retry handler in undici can leave an already‑exposed response body pending indefinitely. When a server replies successfully with a declared Content-Length but sends only part of the body and then closes the connection, the retry handler retries the request. If the retry returns a non‑retryable status such as 400, the handler forwards that new response while replacing its internal response stream, but the original application‑held response body is never ended or destroyed. As a result, any code that reads that body never resolves, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker‑controlled server can exploit this by sending two short responses without keeping a connection open. Repeated requests accumulate unclosed promises and streams, which can exhaust application concurrency or memory, ultimately causing the application to freeze or crash.

Affected Systems

Undici, a popular HTTP client library for Node.js, is affected for all releases from version 7.11.0 through 7.29.1 and from 8.0.0 through 8.10.2. Any application that relies on these undici versions and performs HTTP requests that may trigger retries is impacted.

Risk and Exploitability

The CVSS score of 5.9 reflects moderate severity. EPSS is not available, indicating that public evaluation of exploitation probability is lacking. The vulnerability is not yet listed in the CISA KEV catalog. If exploited, the attack can reserve pending promises and streams until the application runs out of concurrency slots or memory, resulting in a denial of service. The attacker would need control over a server that the target application contacts, sending two short but distinct responses to trigger the retry and subsequent orphaned body. Once the flaw is triggered repeatedly, the application begins to accumulate orphaned resources. While no publicly documented exploit exists as of this report, the nature of the denial of service could be severe for high‑traffic or critical services that depend on undici for HTTP client functionality.

Generated by OpenCVE AI on September 5, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade undici to version 7.29.1 or 8.10.2 to incorporate the fix for orphaned retry handler response bodies.
  • If an immediate upgrade is not possible, disable or limit undici’s retry functionality to reduce the risk of orphaned bodies.
  • Implement monitoring for pending promises or streams, enforce application‑level timeouts, and restart services when thresholds are exceeded to mitigate potential resource exhaustion.

Generated by OpenCVE AI on September 5, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nodejs
Nodejs undici
CPEs cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
Vendors & Products Nodejs
Nodejs undici

Sat, 05 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 04 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Undici
Undici undici
Vendors & Products Undici
Undici undici

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful response that declares a Content-Length, sends only part of the body, and closes the connection, the retry handler retries the request. If the retry returns a non-retryable status such as 400, the handler forwards that new response downstream and replaces its internal response stream, but the original response body that the application still holds is never ended or destroyed. As a result calls that read that body never settle, and the configured body timeout does not fire because its timer is tied to the connection parser rather than the orphaned body. An attacker-controlled server can trigger this with two short responses without keeping a connection open, and repeated requests accumulate pending promises and streams that can exhaust application concurrency or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.
Title undici vulnerable to Denial of Service via orphaned RetryHandler response body
Weaknesses CWE-772
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: openjs

Published:

Updated: 2026-09-04T17:49:50.163Z

Reserved: 2026-07-28T19:16:37.429Z

Link: CVE-2026-18149

cve-icon Vulnrichment

Updated: 2026-09-04T17:49:46.256Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T18:17:49.733

Modified: 2026-09-16T20:41:26.947

Link: CVE-2026-18149

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-04T17:21:46Z

Links: CVE-2026-18149 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T01:30:17Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime

  • CWE-911

    Improper Update of Reference Count