NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1533 most downloaded on npm
An HTTP/1.1 client, written from scratch for Node.js
Last release 9 days ago
25 Sep 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
309 releases · first in 2018
fix(websocket): deprecation warning & 64-bit unsigned int body length by @KhafraDev in https://github.com/nodejs/undici/pull/1818
Full Changelog: https://github.com/nodejs/undici/compare/v5.14.0...v5.15.0
One column per quarter.
fetch: implement https://github.com/whatwg/fetch/pull/1544 by @KhafraDev in https://github.com/nodejs/undici/pull/1780
response-static-error.any.js by @KhafraDev in https://github.com/nodejs/undici/pull/1789Full Changelog: https://github.com/nodejs/undici/compare/v5.13.0...v5.14.0
fix(wpt): move formdata tests to correct folder by @KhafraDev in https://github.com/nodejs/undici/pull/1739
8.2 Set request’s referrer policy on redirect by @metcoder95 in https://github.com/nodejs/undici/pull/1717argumentLengthCheck guard by @KhafraDev in https://github.com/nodejs/undici/pull/1755Full Changelog: https://github.com/nodejs/undici/compare/v5.12.0...v5.13.0
This release includes significant improvements to fetch code coverage and spec compliance as well as a new option to limit response body size.
This release includes significant improvements to fetch code coverage and spec compliance as well as a new option to limit response body size.
Request{Init}.duplex and add WPTs by @KhafraDev in https://github.com/nodejs/undici/pull/1681response WPTs by @KhafraDev in https://github.com/nodejs/undici/pull/1684type more strict by @KhafraDev in https://github.com/nodejs/undici/pull/1703scheme-blob.sub.any.js by @KhafraDev in https://github.com/nodejs/undici/pull/1707Response.json by @KhafraDev in https://github.com/nodejs/undici/pull/1723Full Changelog: https://github.com/nodejs/undici/compare/v5.11.0...v5.12.0
feat: capture error stack traces by @sidwebworks in https://github.com/nodejs/undici/pull/1619
FormData/Blob bodies by @mrbbot in https://github.com/nodejs/undici/pull/1643MockPoolInterceptOptions.method is optional by @KhafraDev in https://github.com/nodejs/undici/pull/1648PoolOptions by @silverwind in https://github.com/nodejs/undici/pull/1651META tags by @KhafraDev in https://github.com/nodejs/undici/pull/1664determineRequestReferrer by @metcoder95 in https://github.com/nodejs/undici/pull/1236Full Changelog: https://github.com/nodejs/undici/compare/v5.10.0...v5.11.0
fix(fetch): allow custom implementation of AbortSignal by @SukkaW in https://github.com/nodejs/undici/pull/1608
ArrayBufferView and ArrayBuffer as body by @LiviaMedeiros in https://github.com/nodejs/undici/pull/1584Full Changelog: https://github.com/nodejs/undici/compare/v5.9.1...v5.10.0
fix: don't timeout while waiting for client to send request
integrity option to Fetch by @jelmervdl in https://github.com/nodejs/undici/pull/1596byteOffset and byteLength by @mrbbot in https://github.com/nodejs/undici/pull/1601Full Changelog: https://github.com/nodejs/undici/compare/v5.8.2...v5.9.1
Nothing published for this version
CRLF Injection in Nodejs ‘undici’ via Content-Type GHSA-f772-66g8-q5h3 CVE-2022-35948
undici.request vulnerable to SSRF using absolute URL on pathname GHSA-8qr4-xgw6-wmr3 CVE-2022-35949Full Changelog: https://github.com/nodejs/undici/compare/v5.8.1...v5.8.2
Do not decode the body while we are following a redirect by @mcollina in https://github.com/nodejs/undici/pull/1554
isErrorLike by @KhafraDev in https://github.com/nodejs/undici/pull/1570Full Changelog: https://github.com/nodejs/undici/compare/v5.8.0...v5.8.1
…CVE CVE-2022-31150, reported by @Haxatron
exclude in CI by @dominykas in https://github.com/nodejs/undici/pull/1544Full Changelog: https://github.com/nodejs/undici/compare/v5.7.0...v5.7.1
fix(fetch): re-add support for node v16.8.0+ by @KhafraDev in https://github.com/nodejs/undici/pull/1534
Headers.prototype.set by @KhafraDev in https://github.com/nodejs/undici/pull/1535Full Changelog: https://github.com/nodejs/undici/compare/v5.6.1...v5.7.0
docs: add example with HEAD method to garbage collection section by @mrkldshv in https://github.com/nodejs/undici/pull/1522
HEAD method to garbage collection section by @mrkldshv in https://github.com/nodejs/undici/pull/1522RequestInit.method by @KhafraDev in https://github.com/nodejs/undici/pull/1529Full Changelog: https://github.com/nodejs/undici/compare/v5.6.0...v5.6.1
build(deps-dev): bump tsd from 0.20.0 to 0.21.0 by @dependabot in https://github.com/nodejs/undici/pull/1493
URL by @SimenB in https://github.com/nodejs/undici/pull/1494fill & constructor by @KhafraDev in https://github.com/nodejs/undici/pull/1502Full Changelog: https://github.com/nodejs/undici/compare/v5.5.1...v5.6.0
This releases fixes CVE CVE-2022-32210. See https://github.com/nodejs/undici/security/advisories/GHSA-pgw7-wx7w-2w33 for more details:
This releases fixes CVE CVE-2022-32210. See https://github.com/nodejs/undici/security/advisories/GHSA-pgw7-wx7w-2w33 for more details:
Undici.ProxyAgent never verifies the remote server's certificate, and always exposes all request & response data to the proxy. This unexpectedly means that proxies can MitM all HTTPS traffic, and if the proxy's URL is HTTP then it also means that nominally HTTPS requests are actually sent via plain-text HTTP between Undici and the proxy server.
Full Changelog: https://github.com/nodejs/undici/compare/v5.5.0...v5.5.1
ci: skip automerge job if user is not dependabot by @Fdawgs in https://github.com/nodejs/undici/pull/1478
TypedArray and DataView as Request body by @LiviaMedeiros in https://github.com/nodejs/undici/pull/1472node-fetch tests by @KhafraDev in https://github.com/nodejs/undici/pull/1486FormData Iterator by @KhafraDev in https://github.com/nodejs/undici/pull/1473Full Changelog: https://github.com/nodejs/undici/compare/v5.4.0...v5.5.0
fix: wait a macrotick to resume without pipelining by @mcollina in https://github.com/nodejs/undici/pull/1465
BodyReadable and Dispatcher correctly by @RA80533 in https://github.com/nodejs/undici/pull/1424type are included in FormData by @petebacondarwin in https://github.com/nodejs/undici/pull/1467Full Changelog: https://github.com/nodejs/undici/compare/v5.3.0...v5.4.0
feat: add myself as a collaborator by @KhafraDev in https://github.com/nodejs/undici/pull/1435
RequestInit properties assignable by @NMinhNguyen in https://github.com/nodejs/undici/pull/1446Response.json by @KhafraDev in https://github.com/nodejs/undici/pull/1452URL class with global reference by @Fdawgs in https://github.com/nodejs/undici/pull/1455instanceof FormData check by @NMinhNguyen in https://github.com/nodejs/undici/pull/1457options.body fn by @KhafraDev in https://github.com/nodejs/undici/pull/1464Full Changelog: https://github.com/nodejs/undici/compare/v5.2.0...v5.3.0
fix: use unknown statusText by default in mocks by @KhafraDev in https://github.com/nodejs/undici/pull/1391
unknown statusText by default in mocks by @KhafraDev in https://github.com/nodejs/undici/pull/1391Headers Iterator by @KhafraDev in https://github.com/nodejs/undici/pull/1423Full Changelog: https://github.com/nodejs/undici/compare/v5.1.1...v5.2.0
fix(mock-utils): match header when using fetch by @KhafraDev in https://github.com/nodejs/undici/pull/1393
Full Changelog: https://github.com/nodejs/undici/compare/v5.1.0...v5.1.1
feat: CORB check. by @hemanth in https://github.com/nodejs/undici/pull/1312
FormData bodies in request by @KhafraDev in https://github.com/nodejs/undici/pull/1332get should return null on unknown header name by @KhafraDev in https://github.com/nodejs/undici/pull/1337lint-pr GitHub action workflow 🕺 by @vinayakkulkarni in https://github.com/nodejs/undici/pull/1356lint-staged for running the lint & test scripts by @vinayakkulkarni in https://github.com/nodejs/undici/pull/1349Full Changelog: https://github.com/nodejs/undici/compare/v5.0.0...v5.1.0
refactor: unify close/destroy by @ronag in https://github.com/nodejs/undici/pull/1278 (semver-major due to an Error code change)
Full Changelog: https://github.com/nodejs/undici/compare/v4.16.0...v5.0.0
fix: remove hash from intercept dispatch key by @galvez in https://github.com/nodejs/undici/pull/1273
Full Changelog: https://github.com/nodejs/undici/compare/v4.15.1...v4.16.0
drop mac os x because it constantly fails by @mcollina in https://github.com/nodejs/undici/pull/1264
Full Changelog: https://github.com/nodejs/undici/compare/v4.15.0...v4.15.1
fix: make fetch's signature spec-compliant by @targos in https://github.com/nodejs/undici/pull/1226
RequestInit doesn't allow explicit undefined by @chlonel in https://github.com/nodejs/undici/pull/1242Full Changelog: https://github.com/nodejs/undici/compare/v4.14.1...v4.15.0
Typo: Trailing Space in README.md by @KhooHaoYit in https://github.com/nodejs/undici/pull/1222
Full Changelog: https://github.com/nodejs/undici/compare/v4.14.0...v4.14.1
A new release with lots of new contributors!
A new release with lots of new contributors!
ProxyAgent by @RA80533 in https://github.com/nodejs/undici/pull/1194File coverage by @RaisinTen in https://github.com/nodejs/undici/pull/1206reply by @suneettipirneni in https://github.com/nodejs/undici/pull/1200Illegal invocations of the FileLike class by @RaisinTen in https://github.com/nodejs/undici/pull/1207manual redirect handling by @RaisinTen in https://github.com/nodejs/undici/pull/1210Full Changelog: https://github.com/nodejs/undici/compare/v4.13.0...v4.14.0
fetch: add blob: & about: uri support by @KhafraDev in https://github.com/nodejs/undici/pull/1165
Full Changelog: https://github.com/nodejs/undici/compare/v4.12.2...v4.13.0
fix: doc anchor by @liuhanqu in https://github.com/nodejs/undici/pull/1156
Full Changelog: https://github.com/nodejs/undici/compare/v4.12.0...v4.12.2
fix(fetch): integration with MockAgent by @gdorsi in https://github.com/nodejs/undici/pull/1149
Full Changelog: https://github.com/nodejs/undici/compare/v4.12.0...v4.12.1
This release contains various fetch improvements and fixes.
This release contains various fetch improvements and fixes.
Full Changelog: https://github.com/nodejs/undici/compare/v4.11.3...v4.12.0
fix: fetch missing abort ref 94b8bae22d44e7fc3a4d99f97fe4ce087f1a20fb
Full Changelog: https://github.com/nodejs/undici/compare/v4.11.2...v4.11.3
fix: unregister finalization by @ronag in https://github.com/nodejs/undici/pull/1130
Full Changelog: https://github.com/nodejs/undici/compare/v4.11.1...v4.11.2
fix Response.clone with null body by @KhafraDev in https://github.com/nodejs/undici/pull/1123
Full Changelog: https://github.com/nodejs/undici/compare/v4.11.0...v4.11.1
feat: BodyReadable.dump by @ronag in https://github.com/nodejs/undici/pull/1118
Full Changelog: https://github.com/nodejs/undici/compare/v4.10.4...v4.11.0
Nothing published for this version
fix: update wasi by @ronag in https://github.com/nodejs/undici/pull/1101
Full Changelog: https://github.com/nodejs/undici/compare/v4.10.2...v4.10.3
fix: add npm keywords by @ronag in https://github.com/nodejs/undici/pull/1107
Full Changelog: https://github.com/nodejs/undici/compare/v4.10.1...v4.10.2
feat: accept third-party Blobs in FormData by @wojpawlik in https://github.com/nodejs/undici/pull/1099
Blobs in FormData by @wojpawlik in https://github.com/nodejs/undici/pull/1099status and statusText like Web fetch by @gzuidhof in https://github.com/nodejs/undici/pull/1100Full Changelog: https://github.com/nodejs/undici/compare/v4.10.0...v4.10.1
build(deps-dev): bump github actions by @Fdawgs in https://github.com/nodejs/undici/pull/1084
Full Changelog: https://github.com/nodejs/undici/compare/v4.9.5...v4.10.0
add fetch to namespace by @Ethan-Arrowood in https://github.com/nodejs/undici/pull/1083
Full Changelog: https://github.com/nodejs/undici/compare/v4.9.4...v4.9.5
fix: support no servername by @ronag in https://github.com/nodejs/undici/pull/1082
Full Changelog: https://github.com/nodejs/undici/compare/v4.9.3...v4.9.4
fix: remove busy by @ronag in https://github.com/nodejs/undici/pull/1078
Full Changelog: https://github.com/nodejs/undici/compare/v4.9.2...v4.9.3
fix: use WebAssembly.instantiate by @ronag in https://github.com/nodejs/undici/pull/1077
Full Changelog: https://github.com/nodejs/undici/compare/v4.9.1...v4.9.2
fix: only throw error responses by @ronag in https://github.com/nodejs/undici/pull/1076
Full Changelog: https://github.com/nodejs/undici/compare/v4.9.0...v4.9.1
feat: add max request per client by @RafaelGSS in https://github.com/nodejs/undici/pull/1074
Full Changelog: https://github.com/nodejs/undici/compare/v4.8.2...v4.9.0
feat: add proxy-agent by @RafaelGSS in https://github.com/nodejs/undici/pull/1070
Full Changelog: https://github.com/nodejs/undici/compare/v4.8.1...v4.8.2
Avoid the stream/web warning in Node v16. by @mcollina in https://github.com/nodejs/undici/pull/1068
Full Changelog: https://github.com/nodejs/undici/compare/v4.8.0...v4.8.1
Implements BalancedPool by @mcollina in https://github.com/nodejs/undici/pull/1064
Full Changelog: https://github.com/nodejs/undici/compare/v4.7.3...v4.8.0
Support for Node v17 by @mcollina in https://github.com/nodejs/undici/pull/1063
Full Changelog: https://github.com/nodejs/undici/compare/v4.7.2...v4.7.3
fix: don't rely on allowSyntheticDefaultImports by @RA80533 in https://github.com/nodejs/undici/pull/1059
allowSyntheticDefaultImports by @RA80533 in https://github.com/nodejs/undici/pull/1059Full Changelog: https://github.com/nodejs/undici/compare/v4.7.1...v4.7.2
Nothing published for this version
Expose the socket in case of SocketError by @delvedor in https://github.com/nodejs/undici/pull/1041
File.filename property to File.name by @octet-stream in https://github.com/nodejs/undici/pull/1044File and FormData types declarations. by @octet-stream in https://github.com/nodejs/undici/pull/1042Full Changelog: https://github.com/nodejs/undici/compare/v4.6.0...v4.7.0
BodyMixin.arrayBuffer Buffer -> ArrayBuffer typedefs
Revert incorrect servername fix
Add notes about gc spec compliance
Include final URL in redirect history (#994).
Follow fetch spec in regards to USVString
USVString (#986)Support async iterable body in Request
Request(eeadb5ec6e52c36df2230fcd4719215b42798fed)# Improvements - FormData
Your coding agent can read these notes before it upgrades. Set up the MCP server →