NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #40 most downloaded on npm
A stand-alone types package for Undici
Last release today
25 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
139 releases · first in 2023
One column per quarter.
fix: apply byte offset on Buffer.from by @ronag in https://github.com/nodejs/undici/pull/4019
onResponseError by @tmair in https://github.com/nodejs/undici/pull/4030EnvHttpProxyAgent as stable by @aduh95 in https://github.com/nodejs/undici/pull/4049Full Changelog: https://github.com/nodejs/undici/compare/v7.3.0...v7.4.0
fix: sqlite null ref by @ronag in https://github.com/nodejs/undici/pull/4016
Full Changelog: https://github.com/nodejs/undici/compare/v7.2.3...v7.3.0
Fixes CVE CVE-2025-22150 https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975 (embargoed until 22-01-2025).
Fixes CVE CVE-2025-22150 https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975 (embargoed until 22-01-2025).
Full Changelog: https://github.com/nodejs/undici/compare/v7.2.2...v7.2.3
Update WPT by @github-actions in https://github.com/nodejs/undici/pull/3991
Full Changelog: https://github.com/nodejs/undici/compare/v7.2.1...v7.2.2
fix(3951): typo on errorede dns lookup by @metcoder95 in https://github.com/nodejs/undici/pull/3956
undici:request:headers does not indicate completion of a response by @legendecas in https://github.com/nodejs/undici/pull/3974Full Changelog: https://github.com/nodejs/undici/compare/v7.2.0...v7.2.1
fix: dns interceptor undefined function by @luddd3 in https://github.com/nodejs/undici/pull/3958
Full Changelog: https://github.com/nodejs/undici/compare/v7.1.1...v7.2.0
fix: publish undicisendHeaders message on H2 by @fengmk2 in https://github.com/nodejs/undici/pull/3921
request + "Garbage Collection" by @WTCT-TOP in https://github.com/nodejs/undici/pull/3916Full Changelog: https://github.com/nodejs/undici/compare/v7.1.0...v7.1.1
Mark http/2 support as stable by @mcollina in https://github.com/nodejs/undici/pull/3893
Full Changelog: https://github.com/nodejs/undici/compare/v7.0.0...v7.1.0
fix: husky deprecation warning by @eXhumer in https://github.com/nodejs/undici/pull/3593
075a5cc to 9af472b in /build by @dependabot in https://github.com/nodejs/undici/pull/33559af472b to 138d0b5 in /build by @dependabot in https://github.com/nodejs/undici/pull/3392BodyReadable.bytes by @tsctx in https://github.com/nodejs/undici/pull/3391138d0b5 to 67225d4 in /build by @dependabot in https://github.com/nodejs/undici/pull/3398duplex docs by @Ethan-Arrowood in https://github.com/nodejs/undici/pull/342267225d4 to 858234a in /build by @dependabot in https://github.com/nodejs/undici/pull/341117e6738 to 30c5be9 in /build by @dependabot in https://github.com/nodejs/undici/pull/344330c5be9 to a20e858 in /build by @dependabot in https://github.com/nodejs/undici/pull/3496a20e858 to a17f484 in /build by @dependabot in https://github.com/nodejs/undici/pull/3542a17f484 to ef7b4bb in /build by @dependabot in https://github.com/nodejs/undici/pull/3547ef7b4bb to 3cb4748 in /build by @dependabot in https://github.com/nodejs/undici/pull/3573pre-commit dependency by @eXhumer in https://github.com/nodejs/undici/pull/3599close on failed WebSocket connection by @eXhumer in https://github.com/nodejs/undici/pull/35663cb4748 to 83b4d7b in /build by @dependabot in https://github.com/nodejs/undici/pull/3621test/fixtures/*.pem by @LiviaMedeiros in https://github.com/nodejs/undici/pull/3659ignoreTrailingSlash to MockAgent and .intercept() by @Uzlopak in https://github.com/nodejs/undici/pull/3655cache prop to RequestInit by @rindeal in https://github.com/nodejs/undici/pull/356983b4d7b to f1b4315 in /build by @dependabot in https://github.com/nodejs/undici/pull/3756nowAbsolute to fast timers by @flakey5 in https://github.com/nodejs/undici/pull/3749Full Changelog: https://github.com/nodejs/undici/compare/v6.19.2...v7.0.0
[v6.x] fix(retry): settle exposed body on terminal failure by @mcollina in #5778
GHSA-rfgv-xxqx-mfg5 : a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the pr
TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 2af0faf8.Content-Range against the original response framing before resuming. Fixed by ce31bc82.Full Changelog: v6.28.0...v6.28.1
GHSA-m8rv-5g2x-5cg5 : a malicious type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content
type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 740a0b7c.Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by cba3a52a, with corrected fixtures in 4fd5a0c6.domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by af748404.GHSA-4cwx-7wf7-3272 and GHSA-jr45-8vmc-qm54 affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.
Full Changelog: v6.27.0...v6.28.0
…fix ( #5308 ) and the version bump, none of the security fixes below.
This release line addresses 4 security advisories.
Action required: Upgrade to undici 6.27.0 or later.
npm install undici@^6.27.0
Note on patched version: the v6 fixes shipped in v6.27.0, not
6.26.0
—v6.26.0contains only the chunked-EOF fix (#5308) and the version bump, none
of the security fixes below.
The v6 line is not affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g,
GHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the
8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).
| Advisory | CVE | Severity (CVSS) | Fixed in | Fix commit |
|---|---|---|---|---|
| GHSA-vxpw-j846-p89q | CVE-2026-12151 | High (7.5) | 6.27.0 | b7f252e7 |
| GHSA-p88m-4jfj-68fv | CVE-2026-9679 | Moderate (5.9) | 6.27.0 | 25efa447 |
| GHSA-g8m3-5g58-fq7m | CVE-2026-11525 | Low (3.7) | 6.27.0 | 25efa447 |
| GHSA-35p6-xmwp-9g52 | CVE-2026-6733 | Low (3.7) | 6.27.0 | f4c31d60 |
GHSA-vxpw-j846-p89q · CWE-400, CWE-770
Fix: b7f252e7 Backport WebSocket maxPayloadSize fixes (#5423, backported to v6 in #5428)
A malicious WebSocket server can stream a large number of small or empty
continuation frames. Undici enforced a limit on cumulative payload size but did
not limit the number of fragments per message, leading to unbounded memory
growth and denial of service. All releases from 6.17.0 onward are affected.
new WebSocket(...) or WebSocketStreamGHSA-p88m-4jfj-68fv · CWE-93
Fix: 25efa447 fix(cookies): preserve values and parse SameSite strictly
parseSetCookie applied percent-decoding to cookie values, turning encoded
sequences like %0D%0A and %00 into literal bytes, contrary to RFC 6265 §5.4
and browser behavior. Applications forwarding parsed Set-Cookie values into
response headers were exposed to header injection, enabling session fixation,
open redirects, and cache poisoning.
;, and =.GHSA-g8m3-5g58-fq7m · CWE-183
Fix: 25efa447 fix(cookies): preserve values and parse SameSite strictly
The cookie parser accepted SameSite values containing Strict, Lax, or
None as substrings rather than requiring exact matches per RFC 6265. Values
like SameSite=NoneOfYourBusiness parsed as None, and SameSite=StrictLax
parsed as Lax, silently weakening cookie security policies for apps that
forward parsed attributes.
GHSA-35p6-xmwp-9g52 · CWE-367 (TOCTOU race condition)
Fix: f4c31d60 fix: guard idle socket validation to skip fresh sockets (#5400)
An attacker controlling an upstream HTTP/1.1 server could inject unsolicited
responses onto idle keep-alive sockets. On socket reuse, the injected response
was associated with a new request, delivering responses to the wrong requests.
keepAliveTimeout: 0 on thev6.27.0 is a security-only release — every change in it is one of the fixes
above, backported to the v6.x maintenance line on purpose:
#5428 — backport of the WebSocket maxPayloadSize fragment-count / cumulative-size limits to v6.x (CVE-2026-12151; this is the v6 counterpart of the v7 backport #5423).#5400 — idle-socket-validation fix for the queue-poisoning issue (CVE-2026-6733).The cookie fix (25efa447,
covering both CVE-2026-9679 and CVE-2026-11525) was applied directly to the v6.x
branch. Full changelog:
v6.26.0...v6.27.0.
Per-advisory credits (as recorded in each GHSA):
fix: validate EOF for chunked h1 responses by @mcollina in https://github.com/nodejs/undici/pull/5308
Full Changelog: https://github.com/nodejs/undici/compare/v6.25.0...v6.26.0
## What's Changed Full Changelog: https://github.com/nodejs/undici/compare/v6.24.1...v6.25.0
Full Changelog: https://github.com/nodejs/undici/compare/v6.24.1...v6.25.0
Full Changelog: https://github.com/nodejs/undici/compare/v6.24.0...v6.24.1
Full Changelog: https://github.com/nodejs/undici/compare/v6.24.0...v6.24.1
This release backports fixes for security vulnerabilities affecting the v6 line.
This release backports fixes for security vulnerabilities affecting the v6 line.
All users on v6 should upgrade to v6.24.0 or later.
GHSA-2mjp-6q6p-2qxm / CVE-2026-1525 (Medium)
Inconsistent interpretation of HTTP requests (request/response smuggling class issue).
GHSA-f269-vfmq-vjvj / CVE-2026-1528 (High)
Malicious WebSocket 64-bit frame length handling could crash the client.
GHSA-4992-7rv2-5pvq / CVE-2026-1527 (Medium)
CRLF injection via the upgrade option.
GHSA-v9p9-hfj2-hcw8 / CVE-2026-2229 (High)
Unhandled exception from invalid server_max_window_bits in WebSocket permessage-deflate negotiation.
GHSA-vrm6-8vpv-qv8q / CVE-2026-1526 (High)
Unbounded memory consumption in WebSocket permessage-deflate decompression.
>= 7.17.0 < 7.24.0 only.< 6.24.0, patched 6.24.0>= 6.0.0 < 6.24.0, patched 6.24.0< 6.24.0, patched 6.24.0< 6.24.0, patched 6.24.0< 6.24.0, patched 6.24.0This fixes https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9 and CVE-2026-22036.
This fixes https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9 and CVE-2026-22036.
Full Changelog: https://github.com/nodejs/undici/compare/v6.22.0...v6.23.0
[Backport v6.x] web: mark as uncloneable when possible (#3709) by @jazelly in https://github.com/nodejs/undici/pull/3744
Full Changelog: https://github.com/nodejs/undici/compare/v6.20.1...v6.21.0
Remove patched dom types (v6.x branch) by @eXhumer in https://github.com/nodejs/undici/pull/3531
v6.x branch) by @eXhumer in https://github.com/nodejs/undici/pull/3531Full Changelog: https://github.com/nodejs/undici/compare/v6.19.8...v6.20.0
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.7...v6.19.8
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.7...v6.19.8
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.5...v6.19.6
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.5...v6.19.6
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.4...v6.19.5
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.4...v6.19.5
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.3...v6.19.4
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.3...v6.19.4
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.2...v6.19.3
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.2...v6.19.3
build: use husky as husky install is deprecated by @jazelly in https://github.com/nodejs/undici/pull/3340
husky as husky install is deprecated by @jazelly in https://github.com/nodejs/undici/pull/3340Full Changelog: https://github.com/nodejs/undici/compare/v6.19.1...v6.19.2
don't append empty origin by @KhafraDev in https://github.com/nodejs/undici/pull/3335
Full Changelog: https://github.com/nodejs/undici/compare/v6.19.0...v6.19.1
don't use internal header state for cookies by @KhafraDev in https://github.com/nodejs/undici/pull/3295
Full Changelog: https://github.com/nodejs/undici/compare/v6.18.1...v6.18.2
docs: Update references to dispatcher in docs by @haikyuu in https://github.com/nodejs/undici/pull/3281
Full Changelog: https://github.com/nodejs/undici/compare/v6.18.0...v6.18.1
permessage-deflate decompression support in websocket by @KhafraDev in https://github.com/nodejs/undici/pull/3263
Full Changelog: https://github.com/nodejs/undici/compare/v6.17.0...v6.18.0
fetch: fix captureStackTrace by @Uzlopak in https://github.com/nodejs/undici/pull/3227
487dc5d to 9e8f45f in /build by @dependabot in https://github.com/nodejs/undici/pull/3271Full Changelog: https://github.com/nodejs/undici/compare/v6.16.1...v6.17.0
fix some typos by @Uzlopak in https://github.com/nodejs/undici/pull/3217
fire-and-forget.js by @tsctx in https://github.com/nodejs/undici/pull/3229Full Changelog: https://github.com/nodejs/undici/compare/v6.16.0...v6.16.1
add index to sequence converter errors by @KhafraDev in https://github.com/nodejs/undici/pull/3178
9459e24 to 487dc5d in /build by @dependabot in https://github.com/nodejs/undici/pull/3195Full Changelog: https://github.com/nodejs/undici/compare/v6.15.0...v6.16.0
Expose EnvHttpProxyAgent to Node.js core bundle, so it can be turned … by @mcollina in https://github.com/nodejs/undici/pull/3148
6d0f18a to db8772d in /build by @dependabot in https://github.com/nodejs/undici/pull/3163Full Changelog: https://github.com/nodejs/undici/compare/v6.14.1...v6.15.0
fix: tweak keep-alive timeout implementation by @mweberxyz in https://github.com/nodejs/undici/pull/3145
ad255c6 to 6d0f18a in /build by @dependabot in https://github.com/nodejs/undici/pull/3154Full Changelog: https://github.com/nodejs/undici/compare/v6.14.0...v6.14.1
bench: enable benchmarks for h2 by @metcoder95 in https://github.com/nodejs/undici/pull/3100
Full Changelog: https://github.com/nodejs/undici/compare/v6.13.0...v6.14.0
build(deps): bump node from 9696b26 to ad255c6 in /build by @dependabot in https://github.com/nodejs/undici/pull/3073
9696b26 to ad255c6 in /build by @dependabot in https://github.com/nodejs/undici/pull/3073ad255c6 to 6d0f18a in /build by @dependabot in https://github.com/nodejs/undici/pull/3096Full Changelog: https://github.com/nodejs/undici/compare/v6.12.0...v6.13.0
fix: broken test by @tsctx in https://github.com/nodejs/undici/pull/3045
577f8eb to 87524df in /build by @dependabot in https://github.com/nodejs/undici/pull/305587524df to 9696b26 in /build by @dependabot in https://github.com/nodejs/undici/pull/3058Full Changelog: https://github.com/nodejs/undici/compare/v6.11.1...v6.12.0
Fixes https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7 CVE-2024-30260
Full Changelog: https://github.com/nodejs/undici/compare/v6.11.0...v6.11.1
refactor(#3023): Pass headers as array instead by @metcoder95 in https://github.com/nodejs/undici/pull/3025
Full Changelog: https://github.com/nodejs/undici/compare/v6.10.2...v6.11.0
Do not fail test if streams support typed arrays by @mcollina in https://github.com/nodejs/undici/pull/2978
Full Changelog: https://github.com/nodejs/undici/compare/v6.10.0...v6.10.2
Full Changelog: https://github.com/nodejs/undici/compare/v6.10.0...v6.10.1
Full Changelog: https://github.com/nodejs/undici/compare/v6.10.0...v6.10.1
test: fix flakyness of issue-803 test by @Uzlopak in https://github.com/nodejs/undici/pull/2960
4999fa1 to 577f8eb in /build by @dependabot in https://github.com/nodejs/undici/pull/2974Full Changelog: https://github.com/nodejs/undici/compare/v6.9.0...v6.10.0
feat: add new dispatch compose by @metcoder95 in https://github.com/nodejs/undici/pull/2826
Full Changelog: https://github.com/nodejs/undici/compare/v6.8.0...v6.9.0
fix: send correct SNI for proxy connections by @chrros95 in https://github.com/nodejs/undici/pull/2939
8bf9240 to 7bfef1d in /build by @dependabot in https://github.com/nodejs/undici/pull/29377bfef1d to 4999fa1 in /build by @dependabot in https://github.com/nodejs/undici/pull/2946Full Changelog: https://github.com/nodejs/undici/compare/v6.7.1...v6.8.0
fetch: use EOL of os-module by @Uzlopak in https://github.com/nodejs/undici/pull/2915
d3271e4 to 8bf9240 in /build by @dependabot in https://github.com/nodejs/undici/pull/2936Full Changelog: https://github.com/nodejs/undici/compare/v6.7.0...v6.7.1
doc deprecate bodymixin.formData by @KhafraDev in https://github.com/nodejs/undici/pull/2892
s/ dispactgher/dispatcher/ by @steveluscher in https://github.com/nodejs/undici/pull/2807fetch is aborted with null as the AbortSignal's reason by @steveluscher in https://github.com/nodejs/undici/pull/2833Full Changelog: https://github.com/nodejs/undici/compare/v6.6.2...v6.7.0
fix: webidl.brandcheck non strict should throw by @Uzlopak in https://github.com/nodejs/undici/pull/2683
Full Changelog: https://github.com/nodejs/undici/compare/v6.6.1...v6.6.2
CVE-2024-24750, Backpressure request ignored in fetch()
Fixes:
Full Changelog: https://github.com/nodejs/undici/compare/v6.6.0...v6.6.1
add webSocket example by @mertcanaltin in https://github.com/nodejs/undici/pull/2626
Full Changelog: https://github.com/nodejs/undici/compare/v6.5.0...v6.6.0
build(deps-dev): bump jsdom from 23.2.0 to 24.0.0 by @dependabot in https://github.com/nodejs/undici/pull/2632
Full Changelog: https://github.com/nodejs/undici/compare/v6.4.0...v6.5.0
refactor: version cleanup by @tsctx in https://github.com/nodejs/undici/pull/2605
balanced-pool, ca-fingerprint, client-abort tests to node:test by @sosukesuzuki in https://github.com/nodejs/undici/pull/2584client-connect, client-dispatch, client-errors test to node:test by @sosukesuzuki in https://github.com/nodejs/undici/pull/2591Full Changelog: https://github.com/nodejs/undici/compare/v6.3.0...v6.4.0
Clear all timeout on destroy and close by @mcollina in https://github.com/nodejs/undici/pull/2535
@matteo.collina/tspl to 0.1.1 by @sosukesuzuki in https://github.com/nodejs/undici/pull/2576abort-controller.js tests to node:test runner by @sosukesuzuki in https://github.com/nodejs/undici/pull/2564async_hooks.js tests to node:test runner by @sosukesuzuki in https://github.com/nodejs/undici/pull/2568agent.js tests to node:test runner by @sosukesuzuki in https://github.com/nodejs/undici/pull/2566abort-event-emitter.js tests to node:test runnner by @sosukesuzuki in https://github.com/nodejs/undici/pull/2565autoselectfamily.js tests to node:test runner by @sosukesuzuki in https://github.com/nodejs/undici/pull/2570NODE_DEBUG by @metcoder95 in https://github.com/nodejs/undici/pull/2585Full Changelog: https://github.com/nodejs/undici/compare/v6.2.1...v6.3.0
perf: use tree by @tsctx in https://github.com/nodejs/undici/pull/2528
Full Changelog: https://github.com/nodejs/undici/compare/v6.2.0...v6.2.1
Remove FinalizationRegistry from Agent by @mcollina in https://github.com/nodejs/undici/pull/2530
Full Changelog: https://github.com/nodejs/undici/compare/v6.1.0...v6.2.0
fix: more sensible stack trace from dump error by @ronag in https://github.com/nodejs/undici/pull/2503
dispatch by @tsctx in https://github.com/nodejs/undici/pull/2493String#toLowerCase call by @tsctx in https://github.com/nodejs/undici/pull/2516Full Changelog: https://github.com/nodejs/undici/compare/v6.0.1...v6.1.0
fix: stream error timings by @ronag in https://github.com/nodejs/undici/pull/2497
Full Changelog: https://github.com/nodejs/undici/compare/v6.0.0...v6.0.1
16 eol by @ronag in https://github.com/nodejs/undici/pull/2480
parseHeaders by @tsctx in https://github.com/nodejs/undici/pull/2492Full Changelog: https://github.com/nodejs/undici/compare/v5.28.2...v6.0.0
Fixes https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7 CVE-2024-30260
Full Changelog: https://github.com/nodejs/undici/compare/v5.28.3...v5.28.4
CVE-2024-24758 Proxy-Authorization header not cleared on cross-origin redirect in fetch
Fixes:
Full Changelog: https://github.com/nodejs/undici/compare/v5.28.2...v5.28.3
Your coding agent can read these notes before it upgrades. Set up the MCP server →