Missing Release of Resource after Effective Lifetime Affecting org.webjars.npm:undici package, versions [7.12.0,]


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.31% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGWEBJARSNPM-19635207
  • published6 Sept 2026
  • disclosed4 Sept 2026
  • creditUnknown

Introduced: 4 Sep 2026

NewCVE-2026-18149  (opens in a new tab)
CWE-772  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

org.webjars.npm:undici is an An HTTP/1.1 client, written from scratch for Node.js

Affected versions of this package are vulnerable to Missing Release of Resource after Effective Lifetime in the RetryHandler, which can leave a response body pending indefinitely when a retried request receives a non-retryable response after a truncated one. An attacker can accumulate unresolved promises and streams until the client is denied service by running a malicious server that repeatedly returns a non-retryable response following a truncated one, so the original response body never resolves and calls like response.body.text() never complete. This requires the application to retry requests through the RetryHandler, and bodyTimeout does not fire because the orphaned body is never active.

Workaround

This vulnerability can be avoided by imposing an independent request deadline and destroying the response body when it expires, since bodyTimeout alone does not release the orphaned body.

CVSS Base Scores

version 4.0
version 3.1