undici npm Package Vulnerabilities Disclosed
- Severity
- HIGH
- Affected component
- undici (npm)
- Affected versions
- < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.28.3 or >= 6.0.0, < 6.6.1 or >= 8.0.0, < 8.5.0 or < 5.8.0 or >= 6.14.0, < 6.19.2 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 2.0.0, < 5.19.1 or < 5.8.2 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 6.0.0, < 6.6.1 or < 5.28.4 or >= 6.0.0, < 6.11.1 or >= 4.5.0, < 5.28.5 or >= 6.0.0, < 6.21.1 or >= 7.0.0, < 7.2.3 or < 5.29.0 or >= 6.0.0, < 6.21.2 or >= 7.0.0, < 7.5.0 or >= 6.0.0, < 6.24.0 or >= 7.0.0, < 7.24.0 or < 5.8.2 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 7.0.0, < 7.18.2 or < 6.23.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.2.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 5.28.4 or >= 6.0.0, < 6.11.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 4.8.2, < 5.5.1 or >= 7.17.0, < 7.24.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.8.0 or < 5.19.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.26.2
- Patched version
- Not yet available
The undici npm package has reportedly two issues in its cache interceptor that may lead to cross-user information disclosure and crashes. Users of affected versions should take immediate action.
What happened
The undici npm package, which is used for HTTP client functionality, has been found to have two distinct issues in its cache interceptor. The first issue involves the potential disclosure of private responses through a shared cache, which could lead to sensitive information being exposed to unauthorized users. The second issue is a parse-time crash that can be triggered by malformed Cache-Control directives. These vulnerabilities are under investigation and have not been exploited in the wild as of the latest reports.
The affected versions of undici are complex and span multiple version ranges. It is critical for users to check their specific version against the provided ranges to determine if an upgrade is necessary. The vulnerabilities have been tracked under the identifier GHSA-4CWX-7WF7-3272.
What to do about it
- Review your project's dependencies to identify if undici is in use and which version is installed.
- Compare your installed version of undici against the affected version ranges provided to assess your exposure.
- If your version is affected, upgrade to the latest version of undici that includes the fix for these issues.
- Monitor the primary sources for any updates on the vulnerabilities and recommended actions.
- Consider implementing additional security measures to mitigate the risk of information disclosure while the fix is being applied.
How 0Day would have caught this
undici is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using undici in versions < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.28.3 or >= 6.0.0, < 6.6.1 or >= 8.0.0, < 8.5.0 or < 5.8.0 or >= 6.14.0, < 6.19.2 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 2.0.0, < 5.19.1 or < 5.8.2 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 6.0.0, < 6.6.1 or < 5.28.4 or >= 6.0.0, < 6.11.1 or >= 4.5.0, < 5.28.5 or >= 6.0.0, < 6.21.1 or >= 7.0.0, < 7.2.3 or < 5.29.0 or >= 6.0.0, < 6.21.2 or >= 7.0.0, < 7.5.0 or >= 6.0.0, < 6.24.0 or >= 7.0.0, < 7.24.0 or < 5.8.2 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 7.0.0, < 7.18.2 or < 6.23.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.2.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 5.28.4 or >= 6.0.0, < 6.11.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 4.8.2, < 5.5.1 or >= 7.17.0, < 7.24.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.8.0 or < 5.19.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.26.2.
What should I do right now?
Immediately check which version of undici you are using. If it falls within the affected ranges, upgrade to the latest version that includes the fix. Monitor the primary sources for updates and consider additional security measures to protect sensitive information.
Where can I find more information about these vulnerabilities?
The primary source for more information is the GitHub Security Advisory GHSA-4CWX-7WF7-3272. It provides detailed information about the vulnerabilities and the affected version ranges.