Intel

AIKIDO-2026-10022

undici is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jan 12, 2026

25

Low Risk

This Affects:

JSundici
7.0.0 - 7.18.1
Fixed in 7.18.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Content-Encoding Chain Resource Exhaustion attack, where a malicious server can send an HTTP response with thousands of layered Content-Encoding headers, forcing the client to undergo excessive recursive decompression that consumes high CPU and memory resources, potentially leading to a denial-of-service. It was mitigated by limiting the permissible chain to 5 encodings.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

undici is vulnerable to Allocation of Resources Without Limits or Throttling in versions 7.0.0 - 7.18.1.

How to fix this

Upgrade the undici library to the patch version.