CVE-2026-84947: undici vulnerable to response truncation via oversized chunked responses in the dump interceptor
undici’s interceptors.dump() reads and discards response bodies up to a configurable maxSize. When a response declares a Content-Length that exceeds maxSize, the request is aborted cleanly. When a response is sent chunked (no Content-Length) and its body exceeds maxSize, it is not aborted: the interceptor ends the response early once the accumulated size reaches maxSize, and continued delivery from the parser triggers an internal assertion that is caught and turned into a request abort and connection tear-down. The application observes a misleading 200 with an empty or truncated body while the connection is disconnected. Any application using the dump interceptor against untrusted or misbehaving upstreams is affected.
References
- cna.openjsf.org/security-advisories.html
- github.com/advisories/GHSA-2gqq-gqf2-x968
- github.com/nodejs/undici/commit/21693f406f0142f3504192e9f9b022dcf84782ae
- github.com/nodejs/undici/commit/6d583124e7cf60b640097d64144ed633cc450584
- github.com/nodejs/undici/releases/tag/v7.29.1
- github.com/nodejs/undici/releases/tag/v8.10.2
- github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
- nvd.nist.gov/vuln/detail/CVE-2026-84947
Code Behaviors & Features
Detect and mitigate CVE-2026-84947 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →