MEDIUMnpm →
undici vulnerable to downstream response desynchronization via retry interceptor
undici vulnerable to downstream response desynchronization via retry interceptor
Affected packages
- undici
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- 0.18%
- EPSS percentile
- 7.3%
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 7%.
Sources
- https://github.com/nodejs/undici/security/advisories/GHSA-8xcm-r25x-g524
- https://nvd.nist.gov/vuln/detail/CVE-2026-16728
- https://github.com/nodejs/undici/commit/1b5a5312c3a7d7a30c31bf0d000b39a8a2531e1c
- https://github.com/nodejs/undici/commit/2b3f749336d356bbbc50192f87f6cf7bc714721a
- https://github.com/nodejs/undici/commit/4a9dafb16ff43880cf590e6d9c2aeee25fbff6d7
- https://github.com/nodejs/undici/commit/4fd5a0c61e627f928b7003adc4ffe1e55ec63420
- https://github.com/nodejs/undici/commit/cba3a52ac2e7abcc4e656d82af8579ea82c2bb9e
- https://github.com/nodejs/undici/commit/e11a68ed4ff345c79402476f7a00d473443e318d
- https://hackerone.com/reports/3828685
- https://cna.openjsf.org/security-advisories.html
- https://github.com/nodejs/undici
- https://github.com/nodejs/undici/releases/tag/v6.28.0
- https://github.com/nodejs/undici/releases/tag/v7.29.0
- https://github.com/nodejs/undici/releases/tag/v8.9.0
Structured record: https://osv.dev/vulnerability/GHSA-8xcm-r25x-g524
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta