Answer in brief
CVE-2026-16728 records a Medium severity (CVSS 4.8) vulnerability in undici vulnerable to downstream response desynchronization via retry interceptor. The current sources do not mark it as known exploited. The current feed maps undici (npm), undici (npm), undici (npm), undici (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 4.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps undici (npm), undici (npm), undici (npm), undici (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| undicinpm | >=7.0.0,<7.29.0 | 7.29.0 |
| undicinpm | >=8.0.0,<8.9.0 | 8.9.0 |
| undicinpm | <6.28.0 | 6.28.0 |
| undicinpm | >=0 <6.28.0 | 6.28.0 |
| undicinpm | >=7.0.0 <7.29.0 | 7.29.0 |
| undicinpm | >=8.0.0 <8.9.0 | 8.9.0 |
Published upstream
Jul 29, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Aug 3, 2026
### Impact Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward upstream response headers and bodies downstream, for example proxy or gateway applications, may emit an invalid HTTP response with a stale `Content-Length` header. This can lead to downstream response desynchronization, connection hangs, or response corruption in clients or intermediaries that rely on the forwarded framing metadata. A malicious or faulty upstream can respond to a range request with a `206 Partial Content` response such as: ```http Content-Range: bytes 0-99/300 Content-Length: 300 ``` and then send only 99 bytes before closing the socket. `interceptors.retry()` can then retry with `Range: bytes=99-99`, receive the final byte, and deliver a 100-byte body to the application while the response headers still contain `Content-Length: 300` from the first response. The bug requires `interceptors.retry()` to be enabled, an upstream that returns a partial response with a mismatched framing header, and a downstream forwarder that does not remove or recalculate `Content-Length`. ### Patches Patched in undici v6.28.0, v7.29.0, and v8.9.0. Users should upgrade to one of these versions or later. ### Workarounds - Disable `interceptors.retry()` for untrusted upstreams. - Remove or recalculate `Content-Length` before forwarding a response body assembled or transformed by Undici.
Quoted source text, attributed separately from HOL analysis.