Skip to content

chore(deps): update dependency undici to v6.24.0 [security]#3438

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-undici-vulnerability
Open

chore(deps): update dependency undici to v6.24.0 [security]#3438
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-undici-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Mar 14, 2026

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
undici (source) 6.21.36.24.0 age confidence

GitHub Vulnerability Alerts

CVE-2026-1528

Impact

A server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process.

Patches

Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade to this version or later.

Workarounds

There are no workarounds.


Release Notes

nodejs/undici (undici)

v6.24.0

Compare Source

What's Changed


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Mar 14, 2026
@renovate renovate bot requested a review from a team as a code owner March 14, 2026 04:46
@renovate renovate bot added the dependencies Pull requests that update a dependency file label Mar 14, 2026
@github-actions github-actions bot requested review from david-luna and trentm March 14, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file pkg:instrumentation-undici

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants