NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #40 most downloaded on npm
A stand-alone types package for Undici
Last release 9 days ago
25 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
139 releases · first in 2023
One column per quarter.
fix: close rejected HTTP/2 WebSocket handshake streams by @mcollina in #5873
Full Changelog: v8.11.1...v8.11.2
deslopify websocket test by @KhafraDev in #5851
Full Changelog: v8.11.0...v8.11.1
fix: complete upgrade diagnostics lifecycle by @BridgeAR in #5761
Full Changelog: v8.10.2...v8.11.0
GHSA-vp8m-p9jh-q5pm : cache and deduplication interceptors could use caller-controlled request metadata instead of the authoritative dispatcher origin
BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by 8f5868fb.TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 66e12816.WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 662d0ea6.Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by cb75bbb3.maxSize. Fixed by 7aac7f12.POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by 2be07bf9.Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 6d583124.Content-Range against the original response framing before resuming. Fixed by 0160a719.Full Changelog: v8.10.1...v8.10.2
fix(mock): re-invoke reply callback for persistent mocks by @mcollina in #5650
Full Changelog: v8.10.0...v8.10.1
feat: namespace h2 options by @metcoder95 in #5498
Full Changelog: v8.9.0...v8.10.0
GHSA-4cwx-7wf7-3272 : malformed qualified private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-t
private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 4fe5bc5f with regression coverage in 9f09b49a.type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 7d3cf924.= in qualified no-cache and private directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by c601fff1.Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by e11a68ed, with corrected fixtures in 2b3f7493.domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 10d93fc3.Undici now validates non-string header values after coercion, including array elements, preventing crafted toString() or Symbol.toPrimitive implementations from introducing CRLF sequences. This defense-in-depth change was made in 354a151f.
Full Changelog: v8.8.0...v8.9.0
fetch: use ReadableStreamTee for cloning streams by @KhafraDev in #5517
Full Changelog: v8.7.0...v8.8.0
test: guard balanced-pool error port lookup by @mcollina in #5463
Full Changelog: v8.6.0...v8.7.0
build(deps-dev): bump proxy from 4.0.0 to 4.1.0 by @dependabot [bot] in #5433
Full Changelog: v8.5.0...v8.6.0
GHSA-vxpw-j846-p89q CVE-2026-12151 High (7.5) 8.5.0 32dbf0b3
This release line addresses 8 security advisories. Most are fixed in
v8.5.0; the SOCKS5 pool-reuse issue was fixed earlier in v8.2.0.
Action required: Upgrade to undici 8.5.0 or later.
npm install undici@^8.5.0
| Advisory | CVE | Severity (CVSS) | Fixed in | Fix commit |
|---|---|---|---|---|
| GHSA-vxpw-j846-p89q | CVE-2026-12151 | High (7.5) | 8.5.0 | 32dbf0b3 |
| GHSA-38rv-x7px-6hhq | CVE-2026-9675 | High (7.5) | 8.5.0 | b4c287b3 |
| GHSA-vmh5-mc38-953g | CVE-2026-9697 | High (7.4) | 8.5.0 | 42d49559 |
| GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | High (7.5) | 8.2.0 | a516f870 |
| GHSA-pr7r-676h-xcf6 | CVE-2026-9678 | Moderate (5.9) | 8.5.0 | cb105d7c |
| GHSA-p88m-4jfj-68fv | CVE-2026-9679 | Moderate (5.9) | 8.5.0 | 5655ea43 |
| GHSA-g8m3-5g58-fq7m | CVE-2026-11525 | Low (3.7) | 8.5.0 | 5655ea43 |
| GHSA-35p6-xmwp-9g52 | CVE-2026-6733 | Low (3.7) | 8.5.0 | 6ea54ef8 |
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix: 32dbf0b3 websocket: limit the number of fragments in a message (also c5ed7875 handle empty fragments and stream limits)
A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service.
new WebSocket(...) or WebSocketStreamGHSA-38rv-x7px-6hhq · CWE-400, CWE-770
Fix: b4c287b3 fix(websocket): enforce max payload size across fragments
Undici validated the size of individual frames but did not track cumulative size
across a fragmented message. An attacker could send many small fragments that
each pass per-frame validation but collectively exceed the configured limit,
causing memory exhaustion. This is a regression introduced in 8.1.0 (the
6.x and 7.x lines are not affected).
GHSA-vmh5-mc38-953g · CWE-295
Fix: 42d49559 fix: honor requestTls when proxy is SOCKS5
The ProxyAgent silently discarded the requestTls option when configured with
a SOCKS5 proxy. TLS connections through the SOCKS5 tunnel ignored user-configured
parameters such as ca, cert, key, rejectUnauthorized, and servername,
falling back to the default Mozilla CA bundle. Applications relying on
certificate pinning to an internal CA were exposed to man-in-the-middle attacks.
ProxyAgent / Socks5ProxyAgent over SOCKS5 that rely onrequestTls.ProxyAgent, whererequestTls functions correctly.GHSA-hm92-r4w5-c3mj · CWE-346 · Fixed in 8.2.0
Fix: a516f870 fix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing (#5041)
Socks5ProxyAgent reused a single connection pool across different origins
without verifying the pool's origin matched the requested origin. This could
route credentials and request data to unintended destinations, cause responses
from the wrong origin to be trusted, and enable HTTPS→HTTP downgrade.
Socks5ProxyAgent across multiple originsGHSA-pr7r-676h-xcf6 · CWE-524
Fix: cb105d7c fix(cache): trim qualified field names
The cache interceptor mishandled responses with whitespace-padded
Cache-Control directives such as private=" authorization". In shared-cache
mode this could cause authenticated data to be cached and served to other users.
Authorization upstream and receive non-canonical qualified directives.Vary: Authorization upstream.GHSA-p88m-4jfj-68fv · CWE-93
Fix: 5655ea43 fix(cookies): preserve values and parse SameSite strictly
parseSetCookie applied percent-decoding to cookie values, turning encoded
sequences like %0D%0A and %00 into literal bytes, contrary to RFC 6265 §5.4
and browser behavior. Applications forwarding parsed Set-Cookie values into
response headers were exposed to header injection, enabling session fixation,
open redirects, and cache poisoning. Introduced in 7.0.0 via
#3789.
;, and =.GHSA-g8m3-5g58-fq7m · CWE-183
Fix: 5655ea43 fix(cookies): preserve values and parse SameSite strictly
The cookie parser accepted SameSite values containing Strict, Lax, or
None as substrings rather than requiring exact matches per RFC 6265. Values
like SameSite=NoneOfYourBusiness parsed as None, and SameSite=StrictLax
parsed as Lax, silently weakening cookie security policies for apps that
forward parsed attributes.
GHSA-35p6-xmwp-9g52 · CWE-367 (TOCTOU race condition)
Fix: 6ea54ef8 fix: guard idle socket validation to skip fresh sockets, hardened by c9fbe9d2 keep idle validation on native timers (#5397) and ac5394b8 keep idle validation on global timers (#5407)
An attacker controlling an upstream HTTP/1.1 server could inject unsolicited
responses onto idle keep-alive sockets. On socket reuse, the injected response
was associated with a new request, delivering responses to the wrong requests.
keepAliveTimeout: 0 on thev8.5.0 shipped the security fixes above alongside the following changes. These
are not security fixes — they are listed for completeness of the release. (The
two queue-poisoning hardening PRs, #5397
and #5407, are covered under
CVE-2026-6733 above and are not repeated here.)
#5408 don't rewind kPendingIdx past in-flight requests · #5391 allow h2 POST request multiplexing · #5406 reap idle HTTP/2 sessions · #5410 preserve h2 queue on out-of-order completion#5416 add bodyMixin.textStream() · #5418 align EventSource with spec#5413 document request header validation · #5383 absorb h2 stream timeout resets (test) · #5420 remove stale repro + lint · #5426 extend Windows CI timeout · #5427 detect available python in WPT runnerFull changelog: v8.4.1...v8.5.0.
Per-advisory credits (as recorded in each GHSA):
test: avoid localhost lookup in fetch cookies tests by @mcollina in https://github.com/nodejs/undici/pull/5363
Full Changelog: https://github.com/nodejs/undici/compare/v8.4.0...v8.4.1
fix: register connect listener before initiating requests in close-and-destroy test by @mcollina in https://github.com/nodejs/undici/pull/5272
npm ci instead of npm install by @aduh95 in https://github.com/nodejs/undici/pull/5315addAbortListener util by @aduh95 in https://github.com/nodejs/undici/pull/5317kEnumerableProperty atomically by @aduh95 in https://github.com/nodejs/undici/pull/5332regex.exec instead of string.match by @aduh95 in https://github.com/nodejs/undici/pull/5331preferH2 connector option to offer h2 first in ALPN by @Antamansid in https://github.com/nodejs/undici/pull/5327Full Changelog: https://github.com/nodejs/undici/compare/v8.3.0...v8.4.0
fix: preserve pool capacity after removing stale client by @trivikr in https://github.com/nodejs/undici/pull/5151
SnapshotAgent: Add normalizeBody and normalizeQuery by @GeoffreyBooth in https://github.com/nodejs/undici/pull/5121Full Changelog: https://github.com/nodejs/undici/compare/v8.2.0...v8.3.0
chore: use native addAbortListener by @trivikr in https://github.com/nodejs/undici/pull/5021
Full Changelog: https://github.com/nodejs/undici/compare/v8.1.0...v8.2.0
feat: add configurable maxPayloadSize for WebSocket by @mcollina in https://github.com/nodejs/undici/pull/4955
Full Changelog: https://github.com/nodejs/undici/compare/v8.0.3...v8.1.0
docs: add an Undici 7 to 8 migration guide by @mcollina in https://github.com/nodejs/undici/pull/4963
dump({ limit: Integer }) default value by @samuel871211 in https://github.com/nodejs/undici/pull/4981dump.maxSize by @samuel871211 in https://github.com/nodejs/undici/pull/4982Full Changelog: https://github.com/nodejs/undici/compare/v8.0.2...v8.0.3
fix(websocket): fallback to HTTP/1.1 when H2 CONNECT is unavailable by @mcollina in https://github.com/nodejs/undici/pull/4966
Full Changelog: https://github.com/nodejs/undici/compare/v8.0.1...v8.0.2
Remove legacy handler wrappers by @mcollina in https://github.com/nodejs/undici/pull/4786
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.7...v8.0.1
Remove legacy handler wrappers by @mcollina in https://github.com/nodejs/undici/pull/4786
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.7...v8.0.0
[Backport v7.x] fix: selectively re-enable SIMD for ppc64 by @github-actions[bot] in #5794
Full Changelog: v7.29.1...v7.30.0
GHSA-w293-vg96-wgc3 : BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate val
BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.maxSize. Fixed by 2c7d7e12.POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.Content-Range against the original response framing before resuming. Fixed by cd8af90b.Full Changelog: v7.29.0...v7.29.1
GHSA-4cwx-7wf7-3272 : malformed qualified private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-t
private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 9f10f1e9, with regression coverage in 466e99d1.type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 33928bc2.= in qualified no-cache and private directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by 98011a86.Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by 1b5a5312, with corrected fixtures in 4a9dafb1.domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 3bf91ddb.Full Changelog: v7.28.0...v7.29.0
The v7 line is not affected by GHSA-38rv-x7px-6hhq ( CVE-2026-9675 ), which is an 8.x-only regression.
This release line addresses 7 security advisories, all shipped in v7.28.0.
Action required: Upgrade to undici 7.28.0 or later.
npm install undici@^7.28.0
The v7 line is not affected by GHSA-38rv-x7px-6hhq (CVE-2026-9675), which is
an 8.x-only regression.
Note on GHSA-hm92-r4w5-c3mj: this fix shipped in v7.28.0, not the
earlier 7.2x line — the vulnerable single-pool code was still present through
v7.27.2. The per-origin pool fix is
3805b8f8(#5041).
| Advisory | CVE | Severity (CVSS) | Fixed in | Fix commit |
|---|---|---|---|---|
| GHSA-vxpw-j846-p89q | CVE-2026-12151 | High (7.5) | 7.28.0 | 8cb10f98 |
| GHSA-vmh5-mc38-953g | CVE-2026-9697 | High (7.4) | 7.28.0 | 04201f89 |
| GHSA-hm92-r4w5-c3mj | CVE-2026-6734 | High (7.5) | 7.28.0 | 3805b8f8 |
| GHSA-pr7r-676h-xcf6 | CVE-2026-9678 | Moderate (5.9) | 7.28.0 | 85a24055 |
| GHSA-p88m-4jfj-68fv | CVE-2026-9679 | Moderate (5.9) | 7.28.0 | d0574cc4 |
| GHSA-g8m3-5g58-fq7m | CVE-2026-11525 | Low (3.7) | 7.28.0 | d0574cc4 |
| GHSA-35p6-xmwp-9g52 | CVE-2026-6733 | Low (3.7) | 7.28.0 | ea8930cf |
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix: 8cb10f98 websocket: limit the number of fragments in a message (part of backport a027a4a0 Backport WebSocket maxPayloadSize fixes to v7.x, #5423)
A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service.
new WebSocket(...) or WebSocketStreamGHSA-vmh5-mc38-953g · CWE-295
Fix: 04201f89 fix: honor requestTls when proxy is SOCKS5 (#5417)
The ProxyAgent silently discarded the requestTls option when configured with
a SOCKS5 proxy. TLS connections through the SOCKS5 tunnel ignored user-configured
parameters such as ca, cert, key, rejectUnauthorized, and servername,
falling back to the default Mozilla CA bundle. Applications relying on
certificate pinning to an internal CA were exposed to man-in-the-middle attacks.
ProxyAgent / Socks5ProxyAgent over SOCKS5 that rely onrequestTls.ProxyAgent, whererequestTls functions correctly.GHSA-hm92-r4w5-c3mj · CWE-346
Fix: 3805b8f8 fix(socks5-proxy-agent): use per-origin pools to prevent cross-origin routing (#5041)
Socks5ProxyAgent reused a single connection pool across different origins
without verifying the pool's origin matched the requested origin. This could
route credentials and request data to unintended destinations, cause responses
from the wrong origin to be trusted, and enable HTTPS→HTTP downgrade.
Socks5ProxyAgent across multiple originsGHSA-pr7r-676h-xcf6 · CWE-524
Fix: 85a24055 fix(cache): trim qualified field names
The cache interceptor mishandled responses with whitespace-padded
Cache-Control directives such as private=" authorization". In shared-cache
mode this could cause authenticated data to be cached and served to other users.
Authorization upstream and receive non-canonical qualified directives.Vary: Authorization upstream.GHSA-p88m-4jfj-68fv · CWE-93
Fix: d0574cc4 fix(cookies): preserve values and parse SameSite strictly
parseSetCookie applied percent-decoding to cookie values, turning encoded
sequences like %0D%0A and %00 into literal bytes, contrary to RFC 6265 §5.4
and browser behavior. Applications forwarding parsed Set-Cookie values into
response headers were exposed to header injection, enabling session fixation,
open redirects, and cache poisoning. Introduced in 7.0.0 via
#3789.
;, and =.GHSA-g8m3-5g58-fq7m · CWE-183
Fix: d0574cc4 fix(cookies): preserve values and parse SameSite strictly
The cookie parser accepted SameSite values containing Strict, Lax, or
None as substrings rather than requiring exact matches per RFC 6265. Values
like SameSite=NoneOfYourBusiness parsed as None, and SameSite=StrictLax
parsed as Lax, silently weakening cookie security policies for apps that
forward parsed attributes.
GHSA-35p6-xmwp-9g52 · CWE-367 (TOCTOU race condition)
Fix: ea8930cf fix: guard idle socket validation to skip fresh sockets, hardened by 8e4046e4 keep idle validation on native timers (#5402) and 0fa80869 keep idle validation on global timers (#5409)
An attacker controlling an upstream HTTP/1.1 server could inject unsolicited
responses onto idle keep-alive sockets. On socket reuse, the injected response
was associated with a new request, delivering responses to the wrong requests.
keepAliveTimeout: 0 on thev7.28.0 is a security-only release — every change in it is one of the fixes
above, backported to the v7.x maintenance line on purpose from the v8
development line:
#5423 — backport of the WebSocket maxPayloadSize fragment-count / cumulative-size limits (CVE-2026-12151).#5402 & #5409 — backport of the idle-validation hardening (native + global timers) for the queue-poisoning fix (CVE-2026-6733).#5417 — requestTls over SOCKS5 fix (CVE-2026-9697).The cookie (d0574cc4),
cache (85a24055) and
queue-poisoning core (ea8930cf)
fixes were applied directly to the v7.x branch. Full changelog:
v7.27.2...v7.28.0.
Per-advisory credits (as recorded in each GHSA):
fix: use legacy global dispatcher in v7 by @mcollina in https://github.com/nodejs/undici/pull/5368
Full Changelog: https://github.com/nodejs/undici/compare/v7.27.1...v7.27.2
fix: preserve raw headers in dispatch handler bridge by @mcollina in https://github.com/nodejs/undici/pull/5345
Full Changelog: https://github.com/nodejs/undici/compare/v7.27.0...v7.27.1
[7.x] fix: support Node 26 and legacy global dispatcher by @mcollina in https://github.com/nodejs/undici/pull/5319
Full Changelog: https://github.com/nodejs/undici/compare/v7.26.0...v7.27.0
fix: backport safe main fixes to v7.x by @mcollina in https://github.com/nodejs/undici/pull/5136
Full Changelog: https://github.com/nodejs/undici/compare/v7.25.0...v7.26.0
## What's Changed Full Changelog: https://github.com/nodejs/undici/compare/v7.24.8...v7.25.0
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.8...v7.25.0
fix: backport 401 stream-backed body fix to v7.x by @mcollina in https://github.com/nodejs/undici/pull/5006
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.7...v7.24.8
docs: update broken links in file "Dispatcher.md" by @samuel871211 in https://github.com/nodejs/undici/pull/4924
redirectionLimitReached by @samuel871211 in https://github.com/nodejs/undici/pull/4933Full Changelog: https://github.com/nodejs/undici/compare/v7.24.6...v7.24.7
fix(test): client wasm compatible with clang 22 by @rozzilla in https://github.com/nodejs/undici/pull/4909
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.5...v7.24.6
Formdata tests by @KhafraDev in https://github.com/nodejs/undici/pull/4902
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.4...v7.24.5
fix(fetch): handle URL credentials in dispatch path extraction by @mcollina in https://github.com/nodejs/undici/pull/4892
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.3...v7.24.4
fix(h2): TypeError: Cannot read properties of null (reading 'push') i… by @hxinhan in https://github.com/nodejs/undici/pull/4881
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.2...v7.24.3
fix fetch path logic by @KhafraDev in https://github.com/nodejs/undici/pull/4890
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.1...v7.24.2
fix: __proto__ pollution by @rahulyadav5524 in https://github.com/nodejs/undici/pull/4885
Full Changelog: https://github.com/nodejs/undici/compare/v7.24.0...v7.24.1
This release addresses multiple security vulnerabilities in Undici.
This release addresses multiple security vulnerabilities in Undici.
All users on v7 should upgrade to v7.24.0 or later.
GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 (Medium)
Inconsistent interpretation of HTTP requests (request/response smuggling class issue).
GHSA-f269-vfmq-vjvj / CVE-2026-1528 (High)
Malicious WebSocket 64-bit frame length handling could crash the client.
GHSA-phc3-fgpg-7m6h / CVE-2026-2581 (Medium)
Unbounded memory consumption in deduplication interceptor response buffering (DoS risk).
GHSA-4992-7rv2-5pvq / CVE-2026-1527 (Medium)
CRLF injection via the upgrade option.
GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 (High)
Unhandled exception from invalid server_max_window_bits in WebSocket permessage-deflate negotiation.
GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 (High)
Unbounded memory consumption in WebSocket permessage-deflate decompression.
7.0.0 < 7.24.0, patched 7.24.07.0.0 < 7.24.0, patched 7.24.0>= 7.17.0 < 7.24.0, patched 7.24.07.0.0 < 7.24.0, patched 7.24.07.0.0 < 7.24.0, patched 7.24.07.0.0 < 7.24.0, patched 7.24.0fix: prevent AbortController GC when redirect is 'error' by @mcollina in https://github.com/nodejs/undici/pull/4750
Full Changelog: https://github.com/nodejs/undici/compare/v7.22.0...v7.23.0
docs: fix syntax highlighting in WebSocket.md by @styfle in https://github.com/nodejs/undici/pull/4814
Full Changelog: https://github.com/nodejs/undici/compare/v7.21.0...v7.22.0
build(deps): bump actions/setup-node from 6.0.0 to 6.2.0 by @dependabot[bot] in https://github.com/nodejs/undici/pull/4796
close method to WebSocketStream interface by @piotr-cz in https://github.com/nodejs/undici/pull/4802Full Changelog: https://github.com/nodejs/undici/compare/v7.20.0...v7.21.0
fix: preserve fetch stack traces by @mcollina in https://github.com/nodejs/undici/pull/4778
Full Changelog: https://github.com/nodejs/undici/compare/v7.19.2...v7.20.0
Minor code cleanups to decompress interceptor by @domenic in https://github.com/nodejs/undici/pull/4754
Full Changelog: https://github.com/nodejs/undici/compare/v7.19.1...v7.19.2
fix: use commit hash when generating release (#4757) by @fenichelar in https://github.com/nodejs/undici/pull/4759
Full Changelog: https://github.com/nodejs/undici/compare/v7.19.0...v7.19.1
fix: Handle FormData body type correctly in RetryAgent retried requests by @eliotschu in https://github.com/nodejs/undici/pull/4692
Full Changelog: https://github.com/nodejs/undici/compare/v7.18.2...v7.19.0
This fixes https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9 and CVE-2026-22036.
This fixes https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9 and CVE-2026-22036.
Full Changelog: https://github.com/nodejs/undici/compare/v7.18.1...v7.18.2
Test and Fix running without SSL by @mcollina in https://github.com/nodejs/undici/pull/4727
Full Changelog: https://github.com/nodejs/undici/compare/v7.18.0...v7.18.1
## What's Changed Full Changelog: https://github.com/nodejs/undici/compare/v7.17.0...v7.18.0
Full Changelog: https://github.com/nodejs/undici/compare/v7.17.0...v7.18.0
chore: extract infra and encoding methods by @Uzlopak in https://github.com/nodejs/undici/pull/4523
'node:' prefix for requiring node built-ins by @Uzlopak in https://github.com/nodejs/undici/pull/4547status in Response.redirect by @gineika in https://github.com/nodejs/undici/pull/4591304 not modified reply upon revalidation did not update cache. by @daan944 in https://github.com/nodejs/undici/pull/4617Full Changelog: https://github.com/nodejs/undici/compare/v7.16.0...v7.17.0
Drop npm token, use OIDC instead by @mcollina in https://github.com/nodejs/undici/pull/4447
[kClose] and [kDestroy], only return Promise by @Uzlopak in https://github.com/nodejs/undici/pull/4450client.connect() sync by @Uzlopak in https://github.com/nodejs/undici/pull/4455BodyReadable.dump by @Uzlopak in https://github.com/nodejs/undici/pull/4459[] instead of new Array(0) by @Uzlopak in https://github.com/nodejs/undici/pull/4435Full Changelog: https://github.com/nodejs/undici/compare/v7.15.0...v7.16.0
feat: extract sri from fetch, upgrade to latest spec by @Uzlopak in https://github.com/nodejs/undici/pull/4307
Full Changelog: https://github.com/nodejs/undici/compare/v7.14.0...v7.15.0
Fix flaky snapshot-testing by @mcollina in https://github.com/nodejs/undici/pull/4367
Full Changelog: https://github.com/nodejs/undici/compare/v7.13.0...v7.14.0
fix: remove deprecated maxRedirections option from types by @mcollina in https://github.com/nodejs/undici/pull/4363
Full Changelog: https://github.com/nodejs/undici/compare/v7.12.0...v7.13.0
test: remove tspl on 2283 test by @Uzlopak in https://github.com/nodejs/undici/pull/4301
@returns everywhere by @Uzlopak in https://github.com/nodejs/undici/pull/4302Full Changelog: https://github.com/nodejs/undici/compare/v7.11.0...v7.12.0
Update WPT by @github-actions in https://github.com/nodejs/undici/pull/4214
node:-prefix by @Uzlopak in https://github.com/nodejs/undici/pull/4256fetch is wrongly typed (#4271) by @bpasero in https://github.com/nodejs/undici/pull/4272Dispatcher.RequestOptions by @IvanDimanov-OfficeRnD in https://github.com/nodejs/undici/pull/4281cleanMocks to MockClient and MockPool by @DemianParkhomenko in https://github.com/nodejs/undici/pull/4176Full Changelog: https://github.com/nodejs/undici/compare/v7.10.0...v7.11.0
Add "clientLifetime" option to close and remove connections from the pool after a specified time. by @dhalbrook in https://github.com/nodejs/undici/pu
pnpm-lock.yaml to .gitignore by @styfle in https://github.com/nodejs/undici/pull/4227Full Changelog: https://github.com/nodejs/undici/compare/v7.9.0...v7.10.0
build(deps): bump step-security/harden-runner from 2.10.2 to 2.11.1 by @dependabot in https://github.com/nodejs/undici/pull/4134
acceptNonStandardSearchParameters MockAgent option by @dario-piotrowicz in https://github.com/nodejs/undici/pull/4148Full Changelog: https://github.com/nodejs/undici/compare/v7.8.0...v7.9.0
cache: more efficient sqlite indices by @ronag in https://github.com/nodejs/undici/pull/4142
Full Changelog: https://github.com/nodejs/undici/compare/v7.7.0...v7.8.0
fix: export UndiciHeaders type and set dispatch headers to UndiciHeaders by @dancastillo in https://github.com/nodejs/undici/pull/3849
Full Changelog: https://github.com/nodejs/undici/compare/v7.6.0...v7.7.0
feat(docs): button to switch dark and light mode by @shivarm in https://github.com/nodejs/undici/pull/4044
Full Changelog: https://github.com/nodejs/undici/compare/v7.4.0...v7.5.0
Your coding agent can read these notes before it upgrades. Set up the MCP server →