undici is vulnerable to Denial of Service (DoS)
59
Medium Risk
WebSocketStream aborts its locked writable on an unclean TCP close and discards the rejection. Aborting a locked writable rejects with a TypeError, and the unobserved rejection terminates the process under Node.js's default unhandledRejection behavior. A remote peer can trigger this with a single connection teardown while the application holds a writer. The fix observes the abort result instead of leaving the rejection unhandled.
You are affected if you are using a version that falls within the vulnerable range and you use WebSocketStream.
undici is vulnerable to Denial of Service (DoS) in versions 7.0.0 - 7.29.0 and 8.0.0 - 8.10.1.
Upgrade the undici library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.