Intel

AIKIDO-2024-10065

undici is vulnerable to Memory Leak

Memory Leak Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 30, 2024

64

Medium Risk

This Affects:

JSundici
4.4.0 - 6.14.1
Fixed in 6.15.0
Are you affected? Scan for Free

TL;DR

Affected versions of the undici library are vulnerable to memory leaks. By making multiple fetch requests with the same AbortSignal, undici adds event listeners without removing them, leading to excessive memory consumption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

undici is vulnerable to Memory Leak in versions 4.4.0 - 6.14.1.

How to fix this

Upgrade the undici library to the patch version.