undici's RetryHandler can leave a response body pending indefinitely. When a retried request receives a non-retryable response after a truncated one, the original response.body held by the application is never settled, so reads such as response.body.text() hang and bodyTimeout does not fire. A malicious server can repeat this to accumulate pending promises and streams, leading to denial of service.
Patched in undici v7.29.1 and v8.10.2.
Impose an independent request deadline and destroy the response body when it expires. bodyTimeout alone does not prevent this.
{
"cwe_ids": [
"CWE-772"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T18:22:34Z",
"nvd_published_at": "2026-09-04T18:17:49Z",
"severity": "MODERATE"
}