HTTP Request Smuggling Affecting undici package, versions <6.28.1>=7.0.0 <7.29.1>=8.0.0 <8.10.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.24% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-UNDICI-19635212
  • published6 Sept 2026
  • disclosed4 Sept 2026
  • creditYuSheng Chen

Introduced: 4 Sep 2026

NewCVE-2026-18540  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade undici to version 6.28.1, 7.29.1, 8.10.2 or higher.

Overview

undici is an An HTTP/1.1 client, written from scratch for Node.js

Affected versions of this package are vulnerable to HTTP Request Smuggling in the interceptors.retry() interceptor, which resumes a partial response and appends the resumed bytes to an already-delivered body, so the delivered body can exceed the declared Content-Length. An attacker can inject bytes beyond the Content-Length into a forwarded response and split the downstream HTTP response by running an upstream that returns a partial response and then resumes it with a Range request, for example a 404 with Content-Length: 2 that sends one byte, closes, then appends 206 Partial Content bytes. This requires the application to enable interceptors.retry(), an untrusted or faulty upstream, and a downstream proxy or gateway that forwards the body without recalculating framing.

Workaround

This vulnerability can be avoided by removing or recalculating Content-Length before forwarding a response body, so a resumed over-length body cannot desynchronize the downstream response.

CVSS Base Scores

version 4.0
version 3.1