Answer in brief
CVE-2026-16728 records a Medium severity security vulnerability in undici vulnerable to downstream response desynchronization via retry interceptor. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
Answer in brief
CVE-2026-16728 records a Medium severity security vulnerability in undici vulnerable to downstream response desynchronization via retry interceptor. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
Update undici to 6.28.0; undici to 7.29.0; undici to 8.9.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-16728 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| undicinpm | <6.28.0 | 6.28.0 |
| undicinpm | >=7.0.0,<7.29.0 | 7.29.0 |
| undicinpm | >=8.0.0,<8.9.0 | 8.9.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-16728 records a Medium severity security vulnerability in undici vulnerable to downstream response desynchronization via retry interceptor. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for undici, undici, undici.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate undici to 6.28.0; undici to 7.29.0; undici to 8.9.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-16728 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| undicinpm | <6.28.0 | 6.28.0 |
| undicinpm | >=7.0.0,<7.29.0 | 7.29.0 |
| undicinpm | >=8.0.0,<8.9.0 | 8.9.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-16728 records a Medium severity security vulnerability in undici vulnerable to downstream response desynchronization via retry interceptor. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for undici, undici, undici.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard### Impact Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale `Content-Length` header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata. A malicious or faulty upstream can respond to a range request with a `206 Partial Content` response such as: ```http Content-Range: bytes 0-99/300 Content-Length: 300 ``` and then send only 99 bytes before closing the socket. `interceptors.retry()` can then retry with `Range: bytes=99-99`, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain `Content-Length: 300` from the first response. The bug requires `interceptors.retry()` to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate `Content-Length`. ### Patches Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later. ### Workarounds - Disable `interceptors.retry()` for untrusted upstreams. - Remove or recalculate `Content-Length` before forwarding a response body assembled or transformed by Undici.
### Impact Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale `Content-Length` header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata. A malicious or faulty upstream can respond to a range request with a `206 Partial Content` response such as: ```http Content-Range: bytes 0-99/300 Content-Length: 300 ``` and then send only 99 bytes before closing the socket. `interceptors.retry()` can then retry with `Range: bytes=99-99`, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain `Content-Length: 300` from the first response. The bug requires `interceptors.retry()` to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate `Content-Length`. ### Patches Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later. ### Workarounds - Disable `interceptors.retry()` for untrusted upstreams. - Remove or recalculate `Content-Length` before forwarding a response body assembled or transformed by Undici.