v7.29.0
⚠️ Security fixes
High severity
- GHSA-4cwx-7wf7-3272: malformed qualified
privateCache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 9f10f1e9, with regression coverage in 466e99d1.
Medium severity
- GHSA-m8rv-5g2x-5cg5: a malicious
typeproperty on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generatedcontent-typeheader. Undici now coerces and validates the value before adding it to the request. Fixed by 33928bc2. - GHSA-jr45-8vmc-qm54: optional whitespace around
=in qualifiedno-cacheandprivatedirectives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by 98011a86. - GHSA-8xcm-r25x-g524: the retry interceptor could expose a stale
Content-Lengthafter resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whoseContent-Lengthis inconsistent withContent-Range. Fixed by 1b5a5312, with corrected fixtures in 4a9dafb1. - GHSA-v3r7-h72x-cjcm: unsanitized
domainandunparsedvalues passed tosetCookie()could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 3bf91ddb.
Full Changelog: v7.28.0...v7.29.0