undici is vulnerable to Allocation of Resources Without Limits or Throttling
50
Medium Risk
Affected versions of this package are vulnerable to a Content-Encoding Chain Resource Exhaustion attack, where a malicious server can send an HTTP response with thousands of layered Content-Encoding headers, forcing the client to undergo excessive recursive decompression that consumes high CPU and memory resources, potentially leading to a denial-of-service. It was mitigated by limiting the permissible chain to 5 encodings.
You are affected if you are using a version that falls within the vulnerable range.
undici is vulnerable to Allocation of Resources Without Limits or Throttling in versions 7.0.0 - 7.18.1 and 0.0.1 - 6.22.0.
Upgrade the undici library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant