# undici@8.11.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:17:42.000Z
- Files reviewed: 112
- Findings: 1 medium, 25 low severity findings
- Report: https://security.togoder.click/npm/undici
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package undici@8.11.2 on Oct 6, 2026. An AI review of 112 source files produced 1 medium, 25 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential path traversal / unsafe filename handling

Finding ID: `NPS-A0549B5C7452`

File: `lib/web/fetch/formdata-parser.js:268`

The parser extracts filename values from Content-Disposition headers, including extended RFC 5987 values via decodeURIComponent, and passes them directly into File objects (new File([body], filename, ...)) and form entries. Downstream consumers writing these files to disk without sanitization could be vulnerable to path traversal (e.g., '../../etc/passwd'), though this file itself does not perform file writes.

### [low] Dynamic function composition

Finding ID: `NPS-48073504749D`

File: `lib/dispatcher/dispatcher.js:33`

Interceptors are invoked dynamically at runtime (dispatch = interceptor(dispatch, interceptorOrigin)). If an attacker controls interceptor values, arbitrary code execution within the dispatch chain is possible. However, interceptors are supplied by the caller, not from external input, so risk is limited.

### [low] Proxy-based monkey-patching / interception

Finding ID: `NPS-25108EDD9126`

File: `lib/dispatcher/dispatcher.js:48`

The compose() method wraps the dispatcher instance in a Proxy that intercepts property access and substitutes a custom dispatch function. While common in HTTP client libraries (e.g., undici) for interceptor support, this pattern could be abused to silently alter request behavior if the source were malicious. No evidence of exfiltration or credential access in this file.

### [low] Environment variable harvesting

Finding ID: `NPS-9B0AD1BB8609`

File: `lib/dispatcher/env-http-proxy-agent.js:25`

The code reads HTTP_PROXY, HTTPS_PROXY, http_proxy, https_proxy, NO_PROXY, and no_proxy environment variables. While this is standard behavior for proxy agents (the 'Env' prefix implies environment-based configuration), it does grant the module visibility into the host's proxy configuration, which could be exfiltrated if the module were compromised elsewhere.

### [low] Network routing behavior

Finding ID: `NPS-299F96F5A538`

File: `lib/dispatcher/env-http-proxy-agent.js:30`

The dispatcher constructs ProxyAgent instances pointing at URIs derived from environment variables (HTTP_PROXY/HTTPS_PROXY) and routes outbound requests through them. This is the intended, documented purpose of an EnvHttpProxyAgent, but it does mean all traffic from callers using this agent can be redirected to an attacker-controlled proxy if the environment is compromised.

### [low] Suspicious reference to undefined property

Finding ID: `NPS-4F7B0B02ADF8`

File: `lib/dispatcher/env-http-proxy-agent.js:87`

In #shouldProxy, the code references this.#noProxyChanged (line 87 in the file), but the class only defines a getter named #noProxyChanged. Reading this.#noProxyChanged invokes the getter, which is fine, but the naming (a getter used as a boolean flag) is confusing and may indicate an intended caching mechanism that isn't actually implemented. Not malicious, but worth noting for correctness.

### [low] Regex-based hostname parsing

Finding ID: `NPS-76FC1072E56E`

File: `lib/dispatcher/env-http-proxy-agent.js:120`

The NO_PROXY parser uses regexes on untrusted environment input. The patterns are anchored and bounded, so catastrophic backtracking is unlikely, but parsing environment-controlled data with regexes is a minor robustness concern.

### [low] Network connections to user-specified endpoints only

Finding ID: `NPS-76D529519115`

File: `lib/dispatcher/proxy-agent.js`

All network activity (Client/Pool/Agent/Socks5ProxyAgent, buildConnector) is directed at the proxy URI or origin supplied by the caller. No hardcoded external hosts, telemetry, or unexpected endpoints are present.

### [low] Intended proxy credential handling

Finding ID: `NPS-CB1D46A06A87`

File: `lib/dispatcher/proxy-agent.js:145`

The code reads proxy credentials from constructor options (opts.auth, opts.token, URL username/password) and forwards them as Proxy-Authorization headers to the configured proxy. This is expected behavior for a ProxyAgent and does not constitute credential harvesting or exfiltration.

### [low] Explicit security hardening against credential leakage

Finding ID: `NPS-9FD922F79C68`

File: `lib/dispatcher/proxy-agent.js:336`

Contains throwIfProxyAuthIsSent/buildHeaders logic that explicitly prevents users from passing Proxy-Authorization headers per-request (fixes GHSA-6cv7-626c-qhqw), which is a defensive measure rather than a vulnerability.

### [low] Global state manipulation

Finding ID: `NPS-EF7971667F46`

File: `lib/global.js:10`

This module sets and retrieves a global Dispatcher object on globalThis using Symbol.for. This is intentional API design for undici, a widely-used official HTTP client. It does not exfiltrate data, harvest credentials, or execute dynamic code.

### [low] Import-time side effect

Finding ID: `NPS-04A92083F664`

File: `lib/global.js:10`

The module creates and installs a default Agent at import time if no global dispatcher exists. This is a benign initialization side effect consistent with the library's purpose.

### [low] Embedded WebAssembly binary

Finding ID: `NPS-128E14EE48D9`

File: `lib/llhttp/llhttp-wasm.js:5`

The file embeds a large base64-encoded WebAssembly blob (llhttp parser) and lazily decodes it via Buffer.from on first access to module.exports. This is a legitimate pattern used by llhttp (the HTTP parser used by Node.js). The WASM imports only env callbacks typical of llhttp (wasm_on_headers_complete, wasm_on_message_begin, wasm_on_body, etc.), and exports llhttp_* APIs. No suspicious host bindings for file, network, or process access are present in the imports.

### [low] Top-level module execution

Finding ID: `NPS-AE58BF134E57`

File: `lib/llhttp/llhttp-wasm.js:7`

Top-level code defines a getter for module.exports that base64-decodes the embedded blob on demand. There is no eval, no child_process, no network calls, no filesystem access, and no environment/credential harvesting. Execution at import time is limited to defining the property; the decode happens only when exports are accessed.

### [low] base64-encoded WASM binary

Finding ID: `NPS-EBED6DEE6307`

File: `lib/llhttp/llhttp_simd-wasm.js`

The file contains a large base64-encoded WebAssembly binary for llhttp (HTTP parser). This is a standard technique used by llhttp to ship a WASM build. The binary exposes only HTTP-parsing callbacks (on_headers_complete, on_message_begin, on_url, on_status, on_header_field, on_header_value, on_body, on_message_complete) and llhttp API functions. No network, filesystem, process-spawning, or credential-harvesting functionality is present.

### [low] lazy module.exports getter

Finding ID: `NPS-CB03BAB7B6B2`

File: `lib/llhttp/llhttp_simd-wasm.js`

module.exports is redefined with a getter that lazily decodes the base64 WASM payload once. This is a benign pattern to defer the cost of base64 decoding until first use. It executes at import time but performs no I/O or code execution beyond a Buffer.from base64 decode.

### [low] no_malicious_patterns

Finding ID: `NPS-14CB65F5C4CB`

File: `lib/mock/mock-agent.js`

The code is a mock agent implementation for Undici. It only uses local module imports, standard JavaScript constructs, and does not perform any network requests, file I/O, process spawning, dynamic code execution, or credential harvesting. All operations are confined to in-memory dispatcher management and call history tracking.

### [low] file system write

Finding ID: `NPS-FBBDBBF2889D`

File: `lib/mock/snapshot-recorder.js:339`

The snapshot recorder writes request/response data to disk at user-controlled paths via saveSnapshots(), which is expected for a testing/mocking library but does represent persistent file system writes outside the immediate package directory depending on the snapshotPath provided.

### [low] silent error swallowing in flush

Finding ID: `NPS-CB0D94380496`

File: `lib/mock/snapshot-recorder.js:396`

Flush failures are silently ignored via empty catch handlers, which could mask write failures and diagnostics; not malicious but a quality concern.

### [low] auto-flush timer writing data unconditionally

Finding ID: `NPS-3F30C096794B`

File: `lib/mock/snapshot-recorder.js:408`

When autoFlush is enabled, the scheduler periodically writes snapshot contents (which may include request headers, bodies, and responses) to the configured snapshotPath. If snapshotPath points outside the project or sensitive headers are not excluded, this can persist sensitive data to disk.

### [low] Unbounded resource consumption / DoS potential

Finding ID: `NPS-B23CF90B0AFC`

File: `lib/web/fetch/formdata-parser.js:120`

The multipart parser uses input.indexOf to scan for boundaries and processes arbitrarily large bodies without size limits or iteration caps. A maliciously crafted multipart body could cause excessive memory or CPU usage. This is a robustness concern rather than an intentional backdoor.

### [low] Decoding ambiguity in content-disposition attributes

Finding ID: `NPS-2CE9F5B6C8F0`

File: `lib/web/fetch/formdata-parser.js:260`

parseContentDispositionAttribute applies decodeURIComponent to extended (RFC 5987) values and performs ad-hoc percent-decoding replacements (%0A, %0D, %22) on quoted strings. Malformed percent sequences could throw, and the transformation is non-standard, but this is a correctness/robustness issue rather than an exploit vector in this module.

### [low] potentially unsafe decompression logic

Finding ID: `NPS-EFC4742BFBB7`

File: `lib/web/fetch/util.js:756`

The InflateStream class wraps zlib inflate with caller-provided options. While it doesn't expose dynamic code execution or network access, decompressing untrusted streams without size limits could be used for resource exhaustion if callers pass attacker-controlled data. This is normal fetch/undici behavior rather than a malicious pattern.

### [low] File system manipulation

Finding ID: `NPS-4B1646C3655C`

File: `scripts/strip-comments.js:5`

The script reads and overwrites './undici-fetch.js' using readFileSync and writeFileSync. While this is likely a build-time script for encoding conversion (UTF-8 to Latin-1), it modifies a source file in place and could be abused to alter package contents.

### [low] Top-level execution

Finding ID: `NPS-75095FB9BF35`

File: `scripts/strip-comments.js:5`

The script executes file I/O operations at import time (top-level code), which can have side effects when the module is required.

### [low] Encoding conversion

Finding ID: `NPS-B5073923CCF6`

File: `scripts/strip-comments.js:6`

The script uses buffer transcode to convert a file from UTF-8 to Latin-1. This is a legitimate but unusual operation that could theoretically be used to obfuscate or alter code content.

## Files reviewed

- `lib/dispatcher/dispatcher.js` (medium): The file is a standard Dispatcher base class with interceptor composition; no malicious patterns, credential harvesting, network exfiltration, or dynamic code execution were detected.
- `lib/dispatcher/env-http-proxy-agent.js` (medium): The file is a legitimate proxy agent implementation that reads standard proxy environment variables; no exfiltration, credential theft, code execution, or other malicious patterns were found, though it does handle sensitive environment configuration that warrants awareness.
- `lib/mock/snapshot-recorder.js` (medium): No malicious patterns detected; the module is a standard snapshot recorder that performs expected file I/O for saving/loading mock data, with no network exfiltration, credential harvesting, dynamic code execution, or shell spawning.
- `lib/web/fetch/formdata-parser.js` (medium): No malicious patterns (exfiltration, credential harvesting, obfuscation, process spawning) were found; the file is a standard multipart/form-data parser with minor robustness and downstream filename-safety concerns.
- `scripts/strip-comments.js` (medium): Script performs in-place encoding conversion on a local file, which is suspicious but likely benign build tooling; no exfiltration, credential harvesting, or code execution detected.
- `index-fetch.js` (safe): This file is a standard entry point that re-exports undici's fetch/WebSocket/EventSource APIs and only augments stack traces on fetch errors, with no suspicious behavior.
- `index.js` (safe): No malicious patterns detected; this is the standard entry point of the undici HTTP client library with only expected module exports and no exfiltration, obfuscation, or suspicious runtime behavior.
- `lib/api/abort-signal.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/api/api-connect.js` (safe): This is a legitimate undici CONNECT handler implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, dynamic execution, or suspicious network/file operations.
- `lib/api/api-pipeline.js` (safe): No malicious patterns detected
- `lib/api/api-request.js` (safe): No malicious patterns detected; this is a standard HTTP request handler implementation from the undici library with proper input validation and no exfiltration, credential harvesting, code execution, or process spawning.
- `lib/api/api-stream.js` (safe): No malicious patterns detected; the code is a legitimate streaming API handler with no signs of data exfiltration, credential harvesting, dynamic code execution, or other security concerns.
- `lib/api/api-upgrade.js` (safe): No malicious patterns detected; the code is a standard Undici HTTP upgrade handler with no exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution.
- `lib/api/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/api/readable.js` (safe): No malicious patterns detected in this readable stream implementation, which appears to be a legitimate HTTP body consumer utility.
- `lib/cache/memory-cache-store.js` (safe): No malicious patterns detected; the file implements a standard in-memory cache store with no network, filesystem, process, or dynamic code execution concerns.
- `lib/cache/sqlite-cache-store.js` (safe): No malicious patterns detected; the code is a legitimate SQLite-backed HTTP cache store with no data exfiltration, credential harvesting, code execution, or other suspicious behavior.
- `lib/core/connect.js` (safe): No malicious patterns detected; the code is a standard TLS/TCP socket connector implementation from undici.
- `lib/core/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/diagnostics.js` (safe): No malicious patterns detected
- `lib/core/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/request.js` (safe): No malicious patterns detected; the code is a well-structured HTTP request implementation with strict input validation and no signs of exfiltration, credential harvesting, obfuscation, or other security concerns.
- `lib/core/socks5-client.js` (safe): This is a straightforward SOCKS5 client implementation with no malicious patterns, no external calls beyond the provided socket, and no credential harvesting or code execution concerns.
- `lib/core/socks5-utils.js` (safe): No malicious patterns detected
- `lib/core/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/tree.js` (safe): No malicious patterns detected; the code implements a ternary search tree for header name lookups with no network, filesystem, process, or dynamic code execution behavior.
- `lib/core/util.js` (safe): No malicious patterns detected; the code is a standard utility module from undici with no evidence of exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `lib/dispatcher/agent.js` (safe): No malicious patterns detected
- `lib/dispatcher/balanced-pool.js` (safe): No malicious patterns detected in the BalancedPool dispatcher implementation; the code is a legitimate load-balancing pool from the undici HTTP client library.
- `lib/dispatcher/client-h1.js` (safe): This is the legitimate HTTP/1.1 dispatcher from the undici package; it contains no malicious patterns, no obfuscation, no credential harvesting, no external data exfiltration, and no install-time execution.
- `lib/dispatcher/client-h2.js` (safe): No malicious patterns detected; the file is a legitimate undici HTTP/2 client dispatcher with only standard networking, stream, and error-handling logic.
- `lib/dispatcher/client.js` (safe): No malicious patterns detected; the file is a legitimate HTTP client dispatcher implementation (undici) with standard connection handling and no data exfiltration, credential harvesting, obfuscation, or shell execution.
- `lib/dispatcher/dispatcher-base.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/dispatcher/dispatcher1-wrapper.js` (safe): No malicious patterns detected; the code is a legitimate adapter wrapper for a dispatcher with no exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/dispatcher/fixed-queue.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/dispatcher/h2c-client.js` (safe): No malicious patterns detected; the code is a straightforward HTTP/2 cleartext client wrapper with input validation and no exfiltration, obfuscation, or dynamic execution.
- `lib/dispatcher/pool-base.js` (safe): No malicious patterns detected
- `lib/dispatcher/pool.js` (safe): No malicious patterns detected; the code implements a standard connection pool dispatcher for undici with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
- `lib/dispatcher/proxy-agent.js` (safe): This is the legitimate undici ProxyAgent implementation; no data exfiltration, obfuscation, dynamic execution, process spawning, or filesystem abuse patterns were found, and credential handling is limited to user-supplied proxy auth.
- `lib/dispatcher/retry-agent.js` (safe): No malicious patterns detected
- `lib/dispatcher/round-robin-pool.js` (safe): This code implements a round-robin connection pool for HTTP clients and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized process execution.
- `lib/dispatcher/socks5-proxy-agent.js` (safe): No malicious patterns detected; the code is a legitimate SOCKS5 proxy agent implementation with no data exfiltration, credential harvesting, obfuscation, or other security red flags.
- `lib/encoding/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/global.js` (safe): This file is a legitimate undici global dispatcher module with no malicious patterns; it only manages an in-process global HTTP dispatcher and contains no exfiltration, credential harvesting, dynamic execution, or process spawning.
- `lib/handler/cache-handler.js` (safe): No malicious patterns detected; the code is a standard HTTP cache handler implementation with no exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/handler/cache-revalidation-handler.js` (safe): No malicious patterns detected; this is a standard HTTP cache revalidation handler with no network, filesystem, process, or code-execution red flags.
- `lib/handler/decorator-handler.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/handler/deduplication-handler.js` (safe): No malicious patterns detected; the code is a legitimate request deduplication handler with no network, filesystem, process, or dynamic code execution concerns.
- `lib/handler/redirect-handler.js` (safe): No malicious patterns detected; the code implements HTTP redirect handling with proper credential stripping on cross-origin redirects.
- `lib/handler/retry-handler.js` (safe): No malicious patterns detected; this is a legitimate HTTP retry handler implementation from the undici package with no data exfiltration, credential harvesting, obfuscation, or suspicious system-level operations.
- `lib/interceptor/cache.js` (safe): No malicious patterns detected; the code is a legitimate HTTP cache interceptor implementation with no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/interceptor/decompress.js` (safe): This is a legitimate HTTP response decompression interceptor for the undici library with no malicious patterns, no external network calls, no credential harvesting, no dynamic code execution, and no install-time code execution.
- `lib/interceptor/deduplicate.js` (safe): No malicious patterns detected
- `lib/interceptor/dns.js` (safe): No malicious patterns detected; the code is a legitimate DNS interceptor implementation without exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `lib/interceptor/dump.js` (safe): No malicious patterns detected; the code implements a response size limiting interceptor without any exfiltration, obfuscation, or process spawning behaviors.
- `lib/interceptor/redirect.js` (safe): No malicious patterns detected; the code is a standard redirect interceptor for HTTP client libraries with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `lib/interceptor/response-error.js` (safe): No malicious patterns detected; the code is a legitimate undici response error interceptor that parses HTTP error bodies with no external communication, credential access, or dynamic execution.
- `lib/interceptor/retry.js` (safe): No malicious patterns detected
- `lib/llhttp/constants.js` (safe): No malicious patterns detected; the file contains only static HTTP parsing constants and maps with no dynamic execution, network, filesystem, or credential access.
- `lib/llhttp/llhttp-wasm.js` (safe): The file is a thin wrapper that lazily base64-decodes the bundled llhttp WebAssembly HTTP parser; no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, backdoors, or process spawning were detected.
- `lib/llhttp/llhttp_simd-wasm.js` (safe): The file is a benign llhttp WASM shim that lazily base64-decodes an HTTP-parser WebAssembly binary; no exfiltration, credential harvesting, dynamic execution, process spawning, or malicious behavior was found.
- `lib/llhttp/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-agent.js` (safe): No malicious patterns detected; the code is a legitimate mock dispatcher implementation for Undici testing.
- `lib/mock/mock-call-history.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-client.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-interceptor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-pool.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-utils.js` (safe): This is a legitimate undici mock-agent utility module with no malicious patterns, network exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
- `lib/mock/pending-interceptors-formatter.js` (safe): No malicious patterns detected; the code is a benign utility for formatting pending interceptor data using Node.js streams and console.
- `lib/mock/snapshot-agent.js` (safe): No malicious patterns detected; the code implements an HTTP snapshot recording/replay agent using standard Node.js APIs without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
- `lib/mock/snapshot-utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/cache.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/date.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/runtime-features.js` (safe): No malicious patterns detected
- `lib/util/stats.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/timers.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cache/cache.js` (safe): No malicious patterns detected; this is a standard implementation of the Cache API for undici with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `lib/web/cache/cachestorage.js` (safe): No malicious patterns detected
- `lib/web/cache/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cookies/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cookies/index.js` (safe): No malicious patterns detected; the code is a standard cookie handling utility with proper WebIDL validation and no network, filesystem, process, or obfuscation concerns.
- `lib/web/cookies/parse.js` (safe): This is a legitimate RFC 6265 cookie parser implementation with no malicious patterns, network activity, file system access, or dynamic code execution.
- `lib/web/cookies/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/eventsource/eventsource-stream.js` (safe): No malicious patterns detected; the code is a standard EventSource stream parser with no data exfiltration, credential harvesting, dynamic code execution, or other red flags.
- `lib/web/eventsource/eventsource.js` (safe): No malicious patterns detected; the file implements a standard EventSource (Server-Sent Events) client with expected network behavior and no exfiltration, obfuscation, or process execution.
- `lib/web/eventsource/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fetch/body.js` (safe): No malicious patterns detected; the code implements standard Fetch API body extraction logic from the undici HTTP client library.
- `lib/web/fetch/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fetch/data-url.js` (safe): No malicious patterns detected
- `lib/web/fetch/formdata.js` (safe): This is a standard FormData implementation from the undici HTTP client library with no malicious patterns detected.
- `lib/web/fetch/global.js` (safe): No malicious patterns detected; the code simply manages a global origin URL symbol with proper validation.
- `lib/web/fetch/headers.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fetch/index.js` (safe): No malicious patterns detected; this is the standard fetch implementation from the undici package with no signs of exfiltration, credential harvesting, obfuscation, or other red flags.
- `lib/web/fetch/request.js` (safe): The code is a legitimate implementation of the WHATWG Fetch standard's Request class from the undici library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized network/file/process access.
- `lib/web/fetch/response.js` (safe): This is a standard Fetch API Response implementation (part of undici) with no malicious patterns, data exfiltration, obfuscation, or unauthorized system access.
- `lib/web/fetch/util.js` (safe): No malicious patterns detected; the file implements standard WHATWG fetch utilities without exfiltration, credential harvesting, obfuscated code, process spawning, or install-time hooks.
- `lib/web/infra/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/subresource-integrity/subresource-integrity.js` (safe): The code is a legitimate Subresource Integrity (SRI) implementation using Node.js crypto module with no malicious patterns detected.
- `lib/web/webidl/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/websocket/connection.js` (safe): This code implements standard WebSocket connection establishment and closing per the WHATWG WebSockets specification using Node.js built-ins, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation detected.
- `lib/web/websocket/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/websocket/events.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/websocket/frame.js` (safe): No malicious patterns detected; the code implements WebSocket frame masking and construction using standard crypto and buffer operations without external communication, credential access, or dynamic execution.
- `lib/web/websocket/permessage-deflate.js` (safe): No malicious patterns detected
- `lib/web/websocket/receiver.js` (safe): The WebSocket frame parser contains no malicious patterns; it is a standard, well-structured implementation with no data exfiltration, code execution, filesystem access, or process spawning.
- `lib/web/websocket/sender.js` (safe): This code is part of the legitimate undici HTTP client library and contains no malicious patterns; it implements WebSocket frame sending with a queue, using only the provided socket.
- `lib/web/websocket/stream/websocketerror.js` (safe): No malicious patterns detected
- `lib/web/websocket/stream/websocketstream.js` (safe): No malicious patterns detected; the code implements the WebSocketStream API with standard network and stream handling, without any data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/web/websocket/util.js` (safe): No malicious patterns detected; the code implements standard WebSocket utility functions without data exfiltration, obfuscation, or suspicious behavior.
- `lib/web/websocket/websocket.js` (safe): This is a standard WHATWG-compliant WebSocket client implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized process execution.

## Version ranges

None of the 4 scanned versions of undici are flagged high or critical. The latest scanned version, 8.11.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.11.2 (`8.11.2`): medium (Potential path traversal / unsafe filename handling)
- 7.30.0 (`7.30.0`): not scanned
- 7.29.0 (`7.29.0`): medium (Potential path traversal / unsafe filename handling +2 more)
- 7.18.2 (`7.18.2`): not scanned
- 6.27.0 – 6.28.0 (`>=6.27.0 <=6.28.0`): medium (Potential denial of service +2 more)
- 6.21.3 (`6.21.3`): not scanned

## Scanned versions

- [8.11.2](https://security.togoder.click/npm/undici@8.11.2): medium, 2026-10-06T14:17:42.000Z
- [7.29.0](https://security.togoder.click/npm/undici@7.29.0): medium, 2026-10-06T14:24:51.000Z
- [6.28.0](https://security.togoder.click/npm/undici@6.28.0): medium, 2026-10-06T14:10:37.000Z
- [6.27.0](https://security.togoder.click/npm/undici@6.27.0): medium, 2026-10-06T14:23:36.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
