An open index of dependabot pull requests across open source projects.

chore(deps): bump undici from 6.25.0 to 6.27.0

Open
Number: #3
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: July 08, 2026 at 02:11 AM UTC
(14 days ago)
Updated: July 08, 2026 at 02:13 AM UTC
(14 days ago)
Labels:
dependencies javascript
Description:

Bumps undici from 6.25.0 to 6.27.0.

Release notes

Sourced from undici's releases.

v6.27.0

⚠️ Security Release

This release line addresses 4 security advisories.

Action required: Upgrade to undici 6.27.0 or later.

npm install undici@^6.27.0

Note on patched version: the v6 fixes shipped in v6.27.0, not 6.26.0v6.26.0 contains only the chunked-EOF fix (#5308) and the version bump, none of the security fixes below.

The v6 line is not affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g, GHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the 8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).

Summary

Advisory CVE Severity (CVSS) Fixed in Fix commit
GHSA-vxpw-j846-p89q CVE-2026-12151 High (7.5) 6.27.0 b7f252e7
GHSA-p88m-4jfj-68fv CVE-2026-9679 Moderate (5.9) 6.27.0 25efa447
GHSA-g8m3-5g58-fq7m CVE-2026-11525 Low (3.7) 6.27.0 25efa447
GHSA-35p6-xmwp-9g52 CVE-2026-6733 Low (3.7) 6.27.0 f4c31d60

High severity

WebSocket DoS via fragment count bypass — CVE-2026-12151

GHSA-vxpw-j846-p89q · CWE-400, CWE-770 Fix: b7f252e7 Backport WebSocket maxPayloadSize fixes (#5423, backported to v6 in #5428)

A malicious WebSocket server can stream a large number of small or empty continuation frames. Undici enforced a limit on cumulative payload size but did not limit the number of fragments per message, leading to unbounded memory growth and denial of service. All releases from 6.17.0 onward are affected.

  • Affected: applications using new WebSocket(...) or WebSocketStream against untrusted endpoints.
  • Workaround: none — upgrade is required.

Moderate severity

HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Package:
undici
Ecosystem:
npm
Version Change:
6.25.0 → 6.27.0
Update Type:
Minor
Security Advisories
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
GHSA-vmh5-mc38-953g CVE-2026-9697 HIGH
## Impact undici's `ProxyAgent` silently drops the `requestTls` option when configured with a SOCKS5 proxy URI (`socks5://` or `socks://`). The target HTTPS connection through the SOCKS5 tunnel fa...
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
GHSA-pr7r-676h-xcf6 CVE-2026-9678 MODERATE
## Impact Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream `Cache-Control` header uses whitespace-padded qualified `private` or `no-cache` field name...
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
GHSA-38rv-x7px-6hhq CVE-2026-9675 HIGH
## Impact The undici WebSocket client enforces `maxPayloadSize` per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many...
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
GHSA-g8m3-5g58-fq7m CVE-2026-11525 LOW
## Impact When undici parses a `Set-Cookie` header, it accepts any `SameSite` attribute value that contains `Strict`, `Lax`, or `None` as a substring, rather than the case-insensitive exact match ...
undici WebSocket client vulnerable to denial of service via fragment count bypass
GHSA-vxpw-j846-p89q CVE-2026-12151 HIGH
## Impact The undici WebSocket client enforces `maxPayloadSize` on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocke...
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
GHSA-p88m-4jfj-68fv CVE-2026-9679 MODERATE
## Impact undici's cookie parser in `parseSetCookie` percent-decodes cookie values via `qsUnescape`, turning encoded sequences like `%0D%0A`, `%00`, `%3B`, and `%3D` into their literal byte equiva...
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
GHSA-hm92-r4w5-c3mj CVE-2026-6734 HIGH
## Impact When using `Socks5ProxyAgent`, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dis...
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
GHSA-35p6-xmwp-9g52 CVE-2026-6733 LOW
## Impact Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto a...
Technical Details
ID: 16124630
UUID: 4833716335
Node ID: PR_kwDOSXmS6s7vFhs5
Host: GitHub
Repository: zenith1379/Lightweight-University-CMS