undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON
Details
CVE-2026-84961 affects multiple packages. undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. See references for individual vulnerability details.