{"id":"GHSA-2gqq-gqf2-x968","summary":"undici vulnerable to response truncation via oversized chunked responses in the dump interceptor","details":"### Impact\n\nundici's `interceptors.dump()` reads and discards response bodies up to a configurable `maxSize`. When a response declares a `Content-Length` that exceeds `maxSize`, the request is aborted cleanly. When a response is sent chunked (no `Content-Length`) and its body exceeds `maxSize`, it is not aborted: the interceptor ends the response early once the accumulated size reaches `maxSize`, and continued delivery from the parser triggers an internal assertion that is caught and turned into a request abort and connection tear-down. The application observes a misleading `200` with an empty or truncated body while the connection is disconnected. Any application using the dump interceptor against untrusted or misbehaving upstreams is affected.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. The dump interceptor now enforces `maxSize` on both the declared and the received body size, aborting the request with a `RequestAbortedError` instead of returning a truncated response.\n\n### Workarounds\n\nNone. Avoid using `interceptors.dump()` with untrusted upstreams until upgraded.","aliases":["CVE-2026-84947"],"modified":"2026-09-29T18:28:11.302166457Z","published":"2026-09-29T18:18:51Z","database_specific":{"nvd_published_at":"2026-09-04T17:17:02Z","cwe_ids":["CWE-20","CWE-248"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-09-29T18:18:51Z"},"references":[{"type":"WEB","url":"https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84947"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/nodejs/undici"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v7.29.1"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v8.10.2"}],"affected":[{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.1.0"},{"fixed":"7.29.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-2gqq-gqf2-x968/GHSA-2gqq-gqf2-x968.json"}},{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-2gqq-gqf2-x968/GHSA-2gqq-gqf2-x968.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}