Intel

AIKIDO-2026-423483

@whatwg-node/fetch is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-fx6j-g5jf-f2mc Published Yesterday

75

High Risk

This Affects:

JS@whatwg-node/fetch
0.0.1 - 0.12.0
Fixed in 0.12.1
Are you affected? Scan for Free

TL;DR

Node's fetch transport in @whatwg-node/fetch follows HTTP redirects by recursively calling fetchNodeHttp again for every 3xx response with no limit on the number of hops. Request defaults redirect to follow, so a target that keeps returning redirects drives unbounded recursion and memory and resource growth on the Node HTTP path. The patch caps following at 20 redirects and rejects further hops with a TooManyRedirects error.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@whatwg-node/fetch is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.12.0.

How to fix this

Upgrade the @whatwg-node/fetch library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform