chore(deps): bump undici from 6.25.0 to 6.27.0
Type: Pull Request
State: Open
Association: Unknown
Comments: 1
(14 days ago)
(14 days ago)
dependencies javascript
Bumps undici from 6.25.0 to 6.27.0.
Release notes
Sourced from undici's releases.
v6.27.0
⚠️ Security Release
This release line addresses 4 security advisories.
Action required: Upgrade to undici 6.27.0 or later.
npm install undici@^6.27.0Note on patched version: the v6 fixes shipped in v6.27.0, not
6.26.0—v6.26.0contains only the chunked-EOF fix (#5308) and the version bump, none of the security fixes below.The v6 line is not affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g, GHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the 8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).
Summary
Advisory CVE Severity (CVSS) Fixed in Fix commit GHSA-vxpw-j846-p89q CVE-2026-12151 High (7.5) 6.27.0 b7f252e7GHSA-p88m-4jfj-68fv CVE-2026-9679 Moderate (5.9) 6.27.0 25efa447GHSA-g8m3-5g58-fq7m CVE-2026-11525 Low (3.7) 6.27.0 25efa447GHSA-35p6-xmwp-9g52 CVE-2026-6733 Low (3.7) 6.27.0 f4c31d60
High severity
WebSocket DoS via fragment count bypass — CVE-2026-12151
GHSA-vxpw-j846-p89q · CWE-400, CWE-770 Fix:
b7f252e7Backport WebSocket maxPayloadSize fixes (#5423, backported to v6 in #5428)A malicious WebSocket server can stream a large number of small or empty continuation frames. Undici enforced a limit on cumulative payload size but did not limit the number of fragments per message, leading to unbounded memory growth and denial of service. All releases from 6.17.0 onward are affected.
- Affected: applications using
new WebSocket(...)orWebSocketStreamagainst untrusted endpoints.- Workaround: none — upgrade is required.
Moderate severity
HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679
... (truncated)
Commits
551138cBumped v6.27.0 (#5431)b7f252eBackport WebSocket maxPayloadSize fixes to v7.x (#5423) (#5428)25efa44fix(cookies): preserve values and parse SameSite strictlyf4c31d6fix: guard idle socket validation to skip fresh sockets (#5400)768beacBumped v6.26.0 (#5323)7917b25fix: validate EOF for chunked h1 responses (#5308)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Security Advisories
undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
undici WebSocket client vulnerable to denial of service via fragment count bypass
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
Technical Details
| ID: | 16124630 |
| UUID: | 4833716335 |
| Node ID: | PR_kwDOSXmS6s7vFhs5 |
| Host: | GitHub |
| Repository: | zenith1379/Lightweight-University-CMS |