Bumps undici from 5.12.0 to 5.19.1. This update includes security fixes.
Vulnerabilities fixed
Regular Expression Denial of Service in Headers
Impact
The Headers.set() and Headers.append() methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the headerValueNormalize() utility function.
Patches
This vulnerability was patched in v5.19.1.
Workarounds
There is no workaround. Please update to an unaffected version.
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebase will rebase this MR
$dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [undici](https://github.com/nodejs/undici) from 5.12.0 to 5.19.1. **This update includes security fixes.**
<details>
<summary>Vulnerabilities fixed</summary>
<blockquote>
<p><strong>Regular Expression Denial of Service in Headers</strong></p>
<h3>Impact</h3>
<p>The <code>Headers.set()</code> and <code>Headers.append()</code> methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the <code>headerValueNormalize()</code> utility function.</p>
<h3>Patches</h3>
<p>This vulnerability was patched in v5.19.1.</p>
<h3>Workarounds</h3>
<p>There is no workaround. Please update to an unaffected version.</p>
<h3>References</h3>
<ul>
<li><a href="https://hackerone.com/bugs?report_id=1784449">https://hackerone.com/bugs?report_id=1784449</a></li>
</ul>
<h3>Credits</h3>
<p>Carter Snook reported this vulnerability.</p>
<p>Patched versions: 5.19.1
Affected versions: < 5.19.1</p>
</blockquote>
<blockquote>
<p><strong>CRLF Injection in Nodejs ‘undici’ via host</strong></p>
<h3>Impact</h3>
<p>undici library does not protect <code>host</code> HTTP header from CRLF injection vulnerabilities.</p>
<h3>Patches</h3>
<p>This issue was patched in Undici v5.19.1.</p>
<h3>Workarounds</h3>
<p>Sanitize the <code>headers.host</code> string before passing to undici.</p>
<h3>References</h3>
<p>Reported at <a href="https://hackerone.com/reports/1820955">https://hackerone.com/reports/1820955</a>.</p>
<h3>Credits</h3>
<p>Thank you to Zhipeng Zhang (<a href="https://hackerone.com/timon8"><code>@timon8</code></a>) for reporting this vulnerability.</p>
<p>Patched versions: 5.19.1
Affected versions: >= 2.0.0, < 5.19.1</p>
</blockquote>
</details>
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a href="https://github.com/nodejs/undici/releases">undici's releases</a>.</em></p>
<blockquote>
<h2>v5.19.1</h2>
<h2>⚠️ Security Release ⚠️</h2>
<ul>
<li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-r6ch-mqf9-qc9w">Regular Expression Denial of Service in Headers</a> with CVE-2023-24807</li>
<li><a href="https://github.com/nodejs/undici/security/advisories/GHSA-5r9g-qh6m-jxff">CRLF Injection in Nodejs ‘undici’ via host</a> with CVE-2023-23936</li>
</ul>
<p>This release is part of the Node.js security release train: <a href="https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/">https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/</a></p>
<h2>v5.19.0</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(fetch): raise AbortSignal max event listeners by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1910">nodejs/undici#1910</a></li>
<li>fix: content-disposition header parsing by <a href="https://github.com/climba03003"><code>@climba03003</code></a> in <a href="https://github.com/nodejs/undici/pull/1911">nodejs/undici#1911</a></li>
<li>fix: remove test by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1916">nodejs/undici#1916</a></li>
<li>feat: add Headers.prototype.getSetCookie by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1915">nodejs/undici#1915</a></li>
<li>fix(headers): clone getSetCookie list & add getSetCookie type by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1917">nodejs/undici#1917</a></li>
<li>doc(mock): update out-of-date reply documentation by <a href="https://github.com/p9f"><code>@p9f</code></a> in <a href="https://github.com/nodejs/undici/pull/1913">nodejs/undici#1913</a></li>
<li>fix(types): add missing keepAlive params by <a href="https://github.com/SkeLLLa"><code>@SkeLLLa</code></a> in <a href="https://github.com/nodejs/undici/pull/1918">nodejs/undici#1918</a></li>
<li>Make the fetch() abort test pass locally, on Linux and Mac, Node 18/19. by <a href="https://github.com/mcollina"><code>@mcollina</code></a> in <a href="https://github.com/nodejs/undici/pull/1927">nodejs/undici#1927</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/climba03003"><code>@climba03003</code></a> made their first contribution in <a href="https://github.com/nodejs/undici/pull/1911">nodejs/undici#1911</a></li>
<li><a href="https://github.com/p9f"><code>@p9f</code></a> made their first contribution in <a href="https://github.com/nodejs/undici/pull/1913">nodejs/undici#1913</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nodejs/undici/compare/v5.18.0...v5.19.0">https://github.com/nodejs/undici/compare/v5.18.0...v5.19.0</a></p>
<h2>v5.18.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Add ability to set TCP keepalive by <a href="https://github.com/xconverge"><code>@xconverge</code></a> in <a href="https://github.com/nodejs/undici/pull/1904">nodejs/undici#1904</a></li>
<li>use faster timers by <a href="https://github.com/ronag"><code>@ronag</code></a> in <a href="https://github.com/nodejs/undici/pull/1908">nodejs/undici#1908</a></li>
<li>fix: ensure header value is a string by <a href="https://github.com/ronag"><code>@ronag</code></a> in <a href="https://github.com/nodejs/undici/pull/1899">nodejs/undici#1899</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nodejs/undici/compare/v5.17.1...v5.18.0">https://github.com/nodejs/undici/compare/v5.17.1...v5.18.0</a></p>
<h2>v5.17.1</h2>
<h2>What's Changed</h2>
<ul>
<li>fix: bad buffer slice (<a href="https://github.com/nodejs/undici/commit/d2be675575512794dcd41b9683b209fc15368154">https://github.com/nodejs/undici/commit/d2be675575512794dcd41b9683b209fc15368154</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nodejs/undici/compare/v5.17.0...v5.17.1">https://github.com/nodejs/undici/compare/v5.17.0...v5.17.1</a></p>
<h2>v5.17.0</h2>
<h2>What's Changed</h2>
<ul>
<li>fix(wpts): Blob is a global getter in >=v19.x.x by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1880">nodejs/undici#1880</a></li>
<li>doc: fix anchor links dispatcher.stream by <a href="https://github.com/RafaelGSS"><code>@RafaelGSS</code></a> in <a href="https://github.com/nodejs/undici/pull/1881">nodejs/undici#1881</a></li>
<li>wpt: make runner more resilient by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1884">nodejs/undici#1884</a></li>
<li>Make test pass in v19.x by <a href="https://github.com/mcollina"><code>@mcollina</code></a> in <a href="https://github.com/nodejs/undici/pull/1879">nodejs/undici#1879</a></li>
<li>Correct the type of DispatchOptions["headers"] by <a href="https://github.com/pan93412"><code>@pan93412</code></a> in <a href="https://github.com/nodejs/undici/pull/1896">nodejs/undici#1896</a></li>
<li>perf(content-type parser): faster string collector by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1894">nodejs/undici#1894</a></li>
<li>feat: expose content-type parser by <a href="https://github.com/KhafraDev"><code>@KhafraDev</code></a> in <a href="https://github.com/nodejs/undici/pull/1895">nodejs/undici#1895</a></li>
<li>fix(types): Update DispatchOptions type for missing "blocking" by <a href="https://github.com/xconverge"><code>@xconverge</code></a> in <a href="https://github.com/nodejs/undici/pull/1889">nodejs/undici#1889</a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/nodejs/undici/commit/984d53bad97c98529424a7f3bef6be1d0e76d039"><code>984d53b</code></a> Bumped v5.19.1</li>
<li><a href="https://github.com/nodejs/undici/commit/6c32c0fd5b874328e5e1f635e2cc431aa21cddab"><code>6c32c0f</code></a> lint fixes</li>
<li><a href="https://github.com/nodejs/undici/commit/f2324e549943f0b0937b09fb1c0c16cc7c93abdf"><code>f2324e5</code></a> Merge pull request from GHSA-r6ch-mqf9-qc9w</li>
<li><a href="https://github.com/nodejs/undici/commit/a2eff05401358f6595138df963837c24348f2034"><code>a2eff05</code></a> Merge pull request from GHSA-5r9g-qh6m-jxff</li>
<li><a href="https://github.com/nodejs/undici/commit/f5c89e5c87c7d702996b152c4ad86302b60c4181"><code>f5c89e5</code></a> Bumped v5.19.0</li>
<li><a href="https://github.com/nodejs/undici/commit/f7c6c6a4a2aef7ee3b8207c4eeab700cb0cfc7dc"><code>f7c6c6a</code></a> Make the fetch() abort test pass locally, on Linux and Mac, Node 18 and 19 (#...</li>
<li><a href="https://github.com/nodejs/undici/commit/aebb232d22e9adafce015b985093114a95b560f0"><code>aebb232</code></a> fix(types): add missing keepAlive params (<a href="https://github.com/nodejs/undici/issues/1918">#1918</a>)</li>
<li><a href="https://github.com/nodejs/undici/commit/e155c6db5cec9bc577d548fa7c7378013631c79c"><code>e155c6d</code></a> doc(mock): update out-of-date reply documentation (<a href="https://github.com/nodejs/undici/issues/1913">#1913</a>)</li>
<li><a href="https://github.com/nodejs/undici/commit/87fa73498d6014a33989179cfaa4347dcb29600f"><code>87fa734</code></a> fix(headers): clone getSetCookie list & add getSetCookie type (<a href="https://github.com/nodejs/undici/issues/1917">#1917</a>)</li>
<li><a href="https://github.com/nodejs/undici/commit/ba5ef44b71eff5a86a8473850a326ff7392664d3"><code>ba5ef44</code></a> feat: add Headers.prototype.getSetCookie (<a href="https://github.com/nodejs/undici/issues/1915">#1915</a>)</li>
<li>Additional commits viewable in <a href="https://github.com/nodejs/undici/compare/v5.12.0...v5.19.1">compare view</a></li>
</ul>
</details>
<br />
---
<details>
<summary>Dependabot commands</summary>
<br />
You can trigger Dependabot actions by commenting on this MR
- `$dependabot rebase` will rebase this MR
- `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps undici from 5.12.0 to 5.19.1. This update includes security fixes.
Vulnerabilities fixed
Release notes
Sourced from undici's releases.
... (truncated)
Commits
984d53bBumped v5.19.16c32c0flint fixesf2324e5Merge pull request from GHSA-r6ch-mqf9-qc9wa2eff05Merge pull request from GHSA-5r9g-qh6m-jxfff5c89e5Bumped v5.19.0f7c6c6aMake the fetch() abort test pass locally, on Linux and Mac, Node 18 and 19 (#...aebb232fix(types): add missing keepAlive params (#1918)e155c6ddoc(mock): update out-of-date reply documentation (#1913)87fa734fix(headers): clone getSetCookie list & add getSetCookie type (#1917)ba5ef44feat: add Headers.prototype.getSetCookie (#1915)Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebasewill rebase this MR$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflictsadded 2 commits
ad7fe1b6- 1 commit from branchmastera029da8b- Build(deps): [security] bump undici from 5.12.0 to 5.19.1Compare with previous version