NPM · AUGUST 2026 · EARLY WARNING

undici npm Package Vulnerabilities Disclosed

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
undici (npm)
Affected versions
< 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.28.3 or >= 6.0.0, < 6.6.1 or >= 8.0.0, < 8.5.0 or < 5.8.0 or >= 6.14.0, < 6.19.2 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 2.0.0, < 5.19.1 or < 5.8.2 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 6.0.0, < 6.6.1 or < 5.28.4 or >= 6.0.0, < 6.11.1 or >= 4.5.0, < 5.28.5 or >= 6.0.0, < 6.21.1 or >= 7.0.0, < 7.2.3 or < 5.29.0 or >= 6.0.0, < 6.21.2 or >= 7.0.0, < 7.5.0 or >= 6.0.0, < 6.24.0 or >= 7.0.0, < 7.24.0 or < 5.8.2 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 7.0.0, < 7.18.2 or < 6.23.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.2.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 5.28.4 or >= 6.0.0, < 6.11.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 4.8.2, < 5.5.1 or >= 7.17.0, < 7.24.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.8.0 or < 5.19.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.26.2
Patched version
Not yet available
GHSA-4CWX-7WF7-3272

The undici npm package has reportedly two issues in its cache interceptor that may lead to cross-user information disclosure and crashes. Users of affected versions should take immediate action.

What happened

The undici npm package, which is used for HTTP client functionality, has been found to have two distinct issues in its cache interceptor. The first issue involves the potential disclosure of private responses through a shared cache, which could lead to sensitive information being exposed to unauthorized users. The second issue is a parse-time crash that can be triggered by malformed Cache-Control directives. These vulnerabilities are under investigation and have not been exploited in the wild as of the latest reports.

The affected versions of undici are complex and span multiple version ranges. It is critical for users to check their specific version against the provided ranges to determine if an upgrade is necessary. The vulnerabilities have been tracked under the identifier GHSA-4CWX-7WF7-3272.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If undici is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using undici in versions < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.28.3 or >= 6.0.0, < 6.6.1 or >= 8.0.0, < 8.5.0 or < 5.8.0 or >= 6.14.0, < 6.19.2 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 2.0.0, < 5.19.1 or < 5.8.2 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or >= 6.0.0, < 6.6.1 or < 5.28.4 or >= 6.0.0, < 6.11.1 or >= 4.5.0, < 5.28.5 or >= 6.0.0, < 6.21.1 or >= 7.0.0, < 7.2.3 or < 5.29.0 or >= 6.0.0, < 6.21.2 or >= 7.0.0, < 7.5.0 or >= 6.0.0, < 6.24.0 or >= 7.0.0, < 7.24.0 or < 5.8.2 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 7.0.0, < 7.18.2 or < 6.23.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.2.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 5.28.4 or >= 6.0.0, < 6.11.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or >= 4.8.2, < 5.5.1 or >= 7.17.0, < 7.24.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.8.0 or < 5.19.1 or < 6.28.0 or >= 7.0.0, < 7.29.0 or >= 8.0.0, < 8.9.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or >= 7.23.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 6.24.0 or >= 7.0.0, < 7.24.0 or < 6.27.0 or >= 7.0.0, < 7.28.0 or >= 8.0.0, < 8.5.0 or < 5.26.2.

What should I do right now?

Immediately check which version of undici you are using. If it falls within the affected ranges, upgrade to the latest version that includes the fix. Monitor the primary sources for updates and consider additional security measures to protect sensitive information.

Where can I find more information about these vulnerabilities?

The primary source for more information is the GitHub Security Advisory GHSA-4CWX-7WF7-3272. It provides detailed information about the vulnerabilities and the affected version ranges.

Sources

Join the 0Day waitlist →

← Back to all threats