# undici@6.27.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:36.000Z
- Files reviewed: 99
- Findings: 3 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/undici@6.27.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package undici@6.27.0 on Oct 6, 2026. An AI review of 99 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential denial of service

Finding ID: `NPS-93936706AB99`

File: `lib/web/fetch/formdata-parser.js:126`

The multipart parser does not limit resource consumption in several loops and buffer operations. For example, `collectASequenceOfBytes` scans from a given position to the end of input without a maximum length, and `input.indexOf()` could scan large portions of input. An attacker providing a very large multipart/form-data body could cause excessive CPU or memory usage. However, this is a general parser robustness concern, not a malicious pattern.

### [medium] Weak Cryptographic Fallback

Finding ID: `NPS-6E15FB61EAA1`

File: `lib/web/websocket/frame.js:11`

The code attempts to require 'node:crypto' and falls back to a non-cryptographic PRNG using Math.random() if the module is unavailable. Math.random() is not cryptographically secure and would produce predictable WebSocket masking keys, which could weaken WebSocket protocol security (masking keys must be unpredictable per RFC 6455). While this is a graceful degradation fallback rather than intentional malice, it introduces a security weakness in environments without crypto.

### [medium] File system manipulation

Finding ID: `NPS-0836E37DC521`

File: `scripts/strip-comments.js:6`

The script reads a file from a relative path './undici-fetch.js' and then overwrites the same file with transformed content. While this is likely intended to fix encoding issues, it modifies files outside the typical package scope and could corrupt or alter the target file if run unintentionally.

### [low] Debug logging of sensitive connection details

Finding ID: `NPS-1FBCF89B50CA`

File: `lib/core/diagnostics.js`

The code subscribes to diagnostics channels and logs detailed connection information (host, port, protocol) at debug level. While gated behind NODE_DEBUG environment variables, this could expose sensitive network topology or internal hostnames if debug logging is enabled in production or misconfigured. This is a potential information disclosure risk, though it is standard practice for debug logging in libraries like undici.

### [low] Unvalidated regex matching (ReDoS)

Finding ID: `NPS-8A4C9CF50908`

File: `lib/mock/mock-utils.js:17`

matchValue uses user-provided RegExp.test without input bounds. If a malicious or user-provided regex with catastrophic backtracking is used, it could cause denial of service when matching paths or headers. This is a standard library capability but worth noting.

### [low] Dynamic code execution via function callbacks

Finding ID: `NPS-9E7C5BA4B930`

File: `lib/mock/mock-utils.js:238`

The mockDispatch function invokes user-supplied callbacks via mockDispatch.data.callback(opts) and _data({...}), and matchValue executes match as a function. In a testing/mocking library this is expected behavior, but it allows arbitrary code execution if malicious callbacks are injected into the mock dispatch configuration.

### [low] Network fallback bypass of mock isolation

Finding ID: `NPS-94EC76282F49`

File: `lib/mock/mock-utils.js:310`

buildMockDispatch's checkNetConnect function can call originalDispatch, forwarding requests to the real network when the mock does not match. This behavior could bypass test isolation and potentially leak request data if misconfigured by a malicious agent configuration.

### [low] Assertion via node:assert

Finding ID: `NPS-EAF33BE6F0A7`

File: `lib/web/fetch/formdata-parser.js:208`

The code uses `assert` from 'node:assert' for internal invariant checks. While not a direct security flaw in this context, using assertions in production code can lead to abrupt process termination if the invariants are violated (e.g., due to malformed input). This is not malicious, but could be a robustness issue.

### [low] Unbounded file Content-Type and filename

Finding ID: `NPS-72DECFBB24E6`

File: `lib/web/fetch/formdata-parser.js:418`

The parser extracts `contentType` and `filename` without explicit length limits, which could allow memory exhaustion or unexpected behavior when creating File objects. Again, this is a robustness issue, not a security exploit pattern.

### [low] Crypto Dependency Resolution

Finding ID: `NPS-CDE428E2875F`

File: `lib/web/websocket/frame.js:9`

The module imports 'node:crypto' via a conditional require. In normal Node.js runtime 'node:crypto' is always available, so the fallback path is effectively dead code. However, if the package is bundled or executed in a modified environment (e.g., a polyfilled or stubbed crypto module), an attacker could substitute a malicious crypto implementation. There is no integrity check on the resolved module.

### [low] Encoding manipulation

Finding ID: `NPS-46F4BD26B24D`

File: `scripts/strip-comments.js:6`

The script uses Buffer transcode to convert the file from utf8 to latin1 and then writes it back. This could be a benign fix for encoding problems, but it alters the file's content in a way that might hide malicious modifications or introduce subtle changes.

## Files reviewed

- `lib/core/diagnostics.js` (medium): The file contains debug logging of network connection details, which is a minor information disclosure risk, but no malicious patterns such as data exfiltration, credential harvesting, or code execution were detected.
- `lib/mock/mock-utils.js` (medium): The code implements a mocking utility for undici with expected dynamic callback/function invocation patterns, but no clear malicious exfiltration, credential harvesting, obfuscation, or process spawning was found; only low-severity concerns around callback execution and regex matching.
- `lib/web/websocket/frame.js` (medium): This WebSocket frame builder is a legitimate implementation derived from the 'ws' library with no clear malicious intent, but it includes a cryptographically weak Math.random() fallback for mask generation that could reduce security in unusual environments.
- `scripts/strip-comments.js` (medium): The script performs a potentially unsafe in-place file transformation on a relative path, which could be used to alter package files, though no direct exfiltration or code execution is present.
- `index-fetch.js` (safe): No malicious patterns detected; this is a standard entry point for the undici HTTP client library that exports fetch, WebSocket, EventSource, and dispatcher APIs.
- `index.js` (safe): No malicious patterns detected; the file is a standard entry point for the undici HTTP client library.
- `lib/api/abort-signal.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/api/api-connect.js` (safe): No malicious patterns detected; this is legitimate Undici HTTP CONNECT handler code with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity.
- `lib/api/api-pipeline.js` (safe): No malicious patterns detected; the code is a legitimate Undici HTTP pipeline implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `lib/api/api-request.js` (safe): No malicious patterns detected; the code is a legitimate HTTP request handler from the undici library with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
- `lib/api/api-stream.js` (safe): No malicious patterns detected; the code is a legitimate HTTP streaming API handler with standard error handling and no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/api/api-upgrade.js` (safe): No malicious patterns detected
- `lib/api/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/api/readable.js` (safe): No malicious patterns detected in this file; it is a legitimate port of Node.js undici's readable body implementation.
- `lib/api/util.js` (safe): No malicious patterns detected
- `lib/core/connect.js` (safe): No malicious patterns detected; the code implements a standard TCP/TLS connector with session caching and timeout handling.
- `lib/core/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/request.js` (safe): No malicious patterns detected; this is a legitimate HTTP request implementation with input validation and no data exfiltration, dynamic code execution, or suspicious behavior.
- `lib/core/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/tree.js` (safe): This is a benign ternary search tree implementation for HTTP header lookups with no malicious patterns.
- `lib/core/util.js` (safe): No malicious patterns detected; the code is a standard HTTP client utility module (undici) handling URL parsing, headers, and body streams without exfiltration, credential harvesting, or code execution.
- `lib/dispatcher/agent.js` (safe): No malicious patterns detected; the file is a standard HTTP dispatcher agent implementation with expected validation, client pooling, and lifecycle management.
- `lib/dispatcher/balanced-pool.js` (safe): No malicious patterns detected
- `lib/dispatcher/client-h1.js` (safe): No malicious patterns detected
- `lib/dispatcher/client-h2.js` (safe): No malicious patterns detected; the code is a legitimate HTTP/2 client dispatcher implementation from the Undici library.
- `lib/dispatcher/client.js` (safe): This is a standard HTTP client dispatcher implementation from the undici package with no malicious patterns, no obfuscation, no external data exfiltration, no credential harvesting, and no unexpected code execution.
- `lib/dispatcher/dispatcher-base.js` (safe): No malicious patterns detected
- `lib/dispatcher/dispatcher.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/dispatcher/env-http-proxy-agent.js` (safe): No malicious patterns detected; the code is a legitimate proxy agent implementation that reads standard proxy environment variables.
- `lib/dispatcher/fixed-queue.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/dispatcher/pool-base.js` (safe): No malicious patterns detected; the code implements a connection pool dispatcher with standard event handling and queue management, containing no data exfiltration, credential harvesting, obfuscation, or suspicious system/network operations.
- `lib/dispatcher/pool-stats.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/dispatcher/pool.js` (safe): No malicious patterns detected; the code is a standard connection pool dispatcher with no exfiltration, credential harvesting, obfuscation, or process execution.
- `lib/dispatcher/proxy-agent.js` (safe): No malicious patterns detected; the file implements a legitimate HTTP/HTTPS proxy agent for the undici library with proper credential handling, no dynamic code execution, no exfiltration, and no suspicious lifecycle or filesystem behavior.
- `lib/dispatcher/retry-agent.js` (safe): No malicious patterns detected; the code implements a standard retry dispatcher for HTTP requests without suspicious behavior.
- `lib/global.js` (safe): No malicious patterns detected; the code is a standard global dispatcher implementation for the undici HTTP client library with no exfiltration, obfuscation, or other red flags.
- `lib/handler/decorator-handler.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/handler/redirect-handler.js` (safe): No malicious patterns detected; the code implements HTTP redirect handling with proper validation and no exfiltration, credential harvesting, or dynamic code execution.
- `lib/handler/retry-handler.js` (safe): No malicious patterns detected; the code is a legitimate HTTP request retry handler with no exfiltration, credential harvesting, dynamic execution, or process spawning.
- `lib/interceptor/dns.js` (safe): No malicious patterns detected; the code implements a DNS caching and load-balancing interceptor without any suspicious behavior.
- `lib/interceptor/dump.js` (safe): No malicious patterns detected; the code implements a benign dump-size-limiting HTTP interceptor with no external calls, credential access, or dynamic execution.
- `lib/interceptor/redirect-interceptor.js` (safe): No malicious patterns detected; the code is a standard HTTP redirect interceptor with no exfiltration, code execution, or credential access.
- `lib/interceptor/redirect.js` (safe): No malicious patterns detected; the code is a standard HTTP redirect interceptor with no suspicious behavior.
- `lib/interceptor/response-error.js` (safe): No malicious patterns detected
- `lib/interceptor/retry.js` (safe): No malicious patterns detected
- `lib/llhttp/constants.js` (safe): No malicious patterns detected
- `lib/llhttp/llhttp-wasm.js` (safe): The file is a legitimate wasm binary for the llhttp HTTP parser (the same module used by Node.js core), containing only the compiled WebAssembly code with no executable JavaScript malicious patterns at import time.
- `lib/llhttp/llhttp_simd-wasm.js` (safe): This file is a base64-encoded WebAssembly binary for the llhttp HTTP parser (a legitimate dependency of Node.js core), with no malicious patterns such as network exfiltration, credential harvesting, obfuscated code execution, or process spawning.
- `lib/llhttp/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-agent.js` (safe): No malicious patterns detected; this is a standard mock agent implementation for the undici HTTP client library with no data exfiltration, credential harvesting, or dynamic code execution.
- `lib/mock/mock-client.js` (safe): No malicious patterns detected in the mock client implementation.
- `lib/mock/mock-errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-interceptor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-pool.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/mock-symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/mock/pending-interceptors-formatter.js` (safe): No malicious patterns detected; the code is a benign utility for formatting pending interceptor data using Node.js streams and console.
- `lib/mock/pluralizer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util/timers.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cache/cache.js` (safe): No malicious patterns detected
- `lib/web/cache/cachestorage.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cache/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cache/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cookies/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/cookies/index.js` (safe): No malicious patterns detected; the code implements standard cookie parsing and serialization using webidl validation without any exfiltration, dynamic execution, or filesystem/process manipulation.
- `lib/web/cookies/parse.js` (safe): No malicious patterns detected
- `lib/web/cookies/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/eventsource/eventsource-stream.js` (safe): No malicious patterns detected; the file is a legitimate EventSource stream parser from undici with no network, filesystem, or code execution concerns.
- `lib/web/eventsource/eventsource.js` (safe): The code is a standard implementation of the EventSource API (Server-Sent Events) for the undici HTTP client library, with no malicious patterns detected.
- `lib/web/eventsource/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fetch/body.js` (safe): No malicious patterns detected; the code implements standard WHATWG Fetch body handling logic.
- `lib/web/fetch/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fetch/data-url.js` (safe): No malicious patterns detected
- `lib/web/fetch/dispatcher-weakref.js` (safe): No malicious patterns detected; the code is a legitimate compatibility workaround for WeakRef and FinalizationRegistry in Node.js v18.
- `lib/web/fetch/file.js` (safe): No malicious patterns detected; the code is a legitimate implementation of a File-like polyfill with no suspicious behavior.
- `lib/web/fetch/formdata-parser.js` (safe): No malicious patterns detected; the file is a standard multipart/form-data parser with some potential denial-of-service robustness concerns but no data exfiltration, code execution, credential harvesting, or backdoor behavior.
- `lib/web/fetch/formdata.js` (safe): No malicious patterns detected; the file is a standard FormData implementation with only legitimate Web IDL converters and File/Blob handling.
- `lib/web/fetch/global.js` (safe): No malicious patterns detected; the code simply manages a global origin URL symbol with proper validation.
- `lib/web/fetch/headers.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the WHATWG Fetch Headers API from undici-fetch.
- `lib/web/fetch/index.js` (safe): No malicious patterns detected
- `lib/web/fetch/request.js` (safe): No malicious patterns detected; this is a standard WHATWG Fetch Request implementation from undici with no exfiltration, obfuscation, process spawning, or install-time code.
- `lib/web/fetch/response.js` (safe): No malicious patterns detected
- `lib/web/fetch/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fetch/util.js` (safe): No malicious patterns detected; the file implements standard WHATWG Fetch API utilities without suspicious network, filesystem, process, or dynamic execution behavior.
- `lib/web/fetch/webidl.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fileapi/encoding.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fileapi/filereader.js` (safe): No malicious patterns detected; the code is a standard FileReader implementation with WebIDL validation and event handling, with no network, filesystem, process, or dynamic execution concerns.
- `lib/web/fileapi/progressevent.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fileapi/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/fileapi/util.js` (safe): No malicious patterns detected; the file implements standard FileReader/Blob reading operations without exfiltration, credential harvesting, dynamic code execution, or other red flags.
- `lib/web/websocket/connection.js` (safe): No malicious patterns detected
- `lib/web/websocket/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/websocket/events.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/websocket/permessage-deflate.js` (safe): No malicious patterns detected; the code implements standard per-message deflate decompression for WebSocket with payload size limits and no external calls, obfuscation, or process execution.
- `lib/web/websocket/receiver.js` (safe): No malicious patterns detected; this is a legitimate WebSocket frame parser implementation.
- `lib/web/websocket/sender.js` (safe): This is a legitimate WebSocket send queue implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `lib/web/websocket/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/web/websocket/util.js` (safe): No malicious patterns detected; the code implements standard WebSocket protocol utilities without any data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `lib/web/websocket/websocket.js` (safe): No malicious patterns detected in the WebSocket implementation; it follows the WHATWG WebSocket specification with standard imports and no suspicious behavior.

## Version ranges

None of the 4 scanned versions of undici are flagged high or critical. The latest scanned version, 8.11.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.11.2 (`8.11.2`): medium (Potential path traversal / unsafe filename handling)
- 7.30.0 (`7.30.0`): not scanned
- 7.29.0 (`7.29.0`): medium (Potential path traversal / unsafe filename handling +2 more)
- 7.18.2 (`7.18.2`): not scanned
- 6.27.0 – 6.28.0 (`>=6.27.0 <=6.28.0`): medium (Potential denial of service +2 more)
- 6.21.3 (`6.21.3`): not scanned

## Scanned versions

- [8.11.2](https://security.togoder.click/npm/undici@8.11.2): medium, 2026-10-06T14:17:42.000Z
- [7.29.0](https://security.togoder.click/npm/undici@7.29.0): medium, 2026-10-06T14:24:51.000Z
- [6.28.0](https://security.togoder.click/npm/undici@6.28.0): medium, 2026-10-06T14:10:37.000Z
- [6.27.0](https://security.togoder.click/npm/undici@6.27.0): medium, 2026-10-06T14:23:36.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
