Skip to content
This repository was archived by the owner on Sep 1, 2026. It is now read-only.

fix(sec-auto): aikido Fix 18 security issues in undici, @fastify/busboy - #5

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/SEC-AUTOFIX-update-packages-98548543-9l9v
Open

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/SEC-AUTOFIX-update-packages-98548543-9l9v

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Aug 27, 2026 •

Copy link
Copy Markdown

AI AutoFix

These PRs will require human vetting and potentially some fixes to fully integrate with the codebase.

Upgrade undici and @fastify/busboy to fix HTTP request smuggling, decompression DoS attacks, and prototype pollution vulnerabilities.

✅ Code not affected by breaking changes.

✅ No breaking changes from the undici upgrade affect this codebase.

The analysis shows that:

  1. Interceptors: The codebase does not use undici interceptors directly. While kInterceptors appears in the bundled dist/index.js (from the bundled undici dependency), the source code in src/ does not configure or use any interceptor functionality.

  2. throwOnError: Although throwOnError appears in the bundled undici code in dist/index.js, the application code does not pass this option when making HTTP requests. The code only uses high-level APIs from @actions/github (Octokit) which abstracts away undici-specific options.

  3. Node.js 18 support dropped: The action already uses Node.js 24 runtime (as specified in action.yml: using: 'node24'), so dropping Node.js 18 support is not a concern.

  4. Deduplicate interceptor: The codebase does not use the deduplicate interceptor.

  5. Third-party fetch support: The codebase does not use undici's fetch API directly; it only uses @actions/github (Octokit) for GitHub API calls.

The undici dependency is only used indirectly through @actions/http-client (version 2.2.3), which is itself a dependency of @actions/github. The application code exclusively uses high-level GitHub API methods (octokit.rest.*, octokit.paginate) and does not configure any undici-specific options.

All breaking changes by upgrading undici from version 5.29.0 to 7.29.0 (CHANGELOG)

Version Description
7.0.0
Upgraded llhttp to 9.2.0
7.0.0
Dropped interceptors
7.0.0
Dropped throwOnError functionality
7.0.0
Bumped concurrently from 8.2.2 to 9.0.0 in /benchmarks (node < 18 unsupported)
7.0.0
Dropped Node.js v18 support
7.22.0
The deduplicate interceptor no longer deduplicates non-safe HTTP methods by default (previously all methods were deduplicated; now only safe methods like GET are deduplicated by default to prevent unintended behavior with POST, PUT, DELETE, etc.)
✅ 18 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-1525
🚨 CRITICAL
[undici] Duplicate HTTP Content-Length headers with case-variant names are allowed, creating malformed requests that can cause denial of service or enable HTTP request smuggling attacks in inconsistent header interpretation scenarios.
CVE-2026-22036
HIGH
[undici] An unbounded decompression chain vulnerability allows a malicious server to insert thousands of compression steps, causing excessive CPU usage and memory allocation. This results in denial of service through resource exhaustion.
CVE-2026-1526
HIGH
[undici] A malicious WebSocket server can send compressed frames that expand to extremely large sizes in memory without limits, causing denial-of-service through memory exhaustion and process crash. The vulnerability stems from unbounded decompression in the permessage-deflate extension without size validation.
CVE-2026-2229
HIGH
[undici] A malicious WebSocket server can crash the client process by sending an invalid server_max_window_bits parameter in the permessage-deflate extension, causing an uncaught RangeError when creating a zlib decompressor with an out-of-range value.
CVE-2026-16728
MEDIUM
[undici] A retry interceptor vulnerability allows mismatched Content-Length headers and response bodies after retries, enabling downstream response desynchronization and corruption in proxies/gateways that forward upstream headers without recalculation.
CVE-2026-16729
MEDIUM
[undici] The setCookie function fails to sanitize cookie domain values and unparsed entries, allowing attackers to inject additional cookie attributes like SameSite, HttpOnly, and Secure. This can bypass CSRF protections or force/strip security attributes in applications using user-controlled input for cookie configuration.
AIKIDO-2024-10065
MEDIUM
[undici] Affected versions of the undici library are vulnerable to memory leaks. By making multiple fetch requests with the same AbortSignal, undici adds event listeners without removing them, leading to excessive memory consumption.
CVE-2026-9679
MEDIUM
[undici] The cookie parser incorrectly percent-decodes cookie values, allowing encoded sequences like %0D%0A to become literal bytes that enable HTTP response header injection. This permits attackers to inject arbitrary headers (Set-Cookie, Location, Cache-Control) into downstream responses, causing session fixation, open redirects, or cache poisoning in applications that forward parsed cookies to response headers.
CVE-2026-15157
MEDIUM
[undici] A vulnerability allows attackers to inject CRLF sequences into HTTP headers by passing a hand-rolled blob-like request body with an untrusted type property, enabling HTTP request smuggling. This affects applications using undici's request, stream, pipeline, or dispatch methods with duck-typed blob objects derived from user input.
AIKIDO-2026-10022
MEDIUM
[undici] A malicious server can send HTTP responses with excessive layered Content-Encoding headers, forcing the client into recursive decompression that exhausts CPU and memory resources, causing denial-of-service. This was mitigated by limiting the encoding chain to a maximum of 5 layers.
CVE-2026-1527
MEDIUM
[undici] HTTP request smuggling vulnerability allowing CRLF injection through the upgrade option, enabling arbitrary header injection and premature request termination to smuggle data to non-HTTP services.
CVE-2026-11525
LOW
[undici] Set-Cookie header parsing accepts non-spec SameSite values containing substrings like "Strict" or "None" instead of exact matches, allowing malicious servers to downgrade cookie security policies. This enables attackers to weaken SameSite enforcement through substring matching exploitation.
CVE-2026-6733
LOW
[undici] HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets, allowing an attacker-controlled upstream server to inject unsolicited responses that get associated with subsequent requests, causing responses to be delivered to wrong requests.
AIKIDO-2026-10369
LOW
[undici] Prototype pollution vulnerability allows attackers to modify object prototypes through specially crafted input with keys like __proto__ or constructor, potentially influencing application behavior or enabling further attacks.
AIKIDO-2026-10385
LOW
[undici] A prototype pollution vulnerability allows attackers to inject special keys like __proto__, constructor, or prototype into internal objects, potentially modifying the prototype chain and influencing application behavior or enabling further attacks.
AIKIDO-2026-87401
HIGH
[@fastify/busboy] A prototype pollution vulnerability in the multipart header parser allows an attacker to send malicious headers (__proto__ or constructor) that cause a TypeError, resulting in denial of service by crashing the Node.js process when using direct write/end operations.
AIKIDO-2026-961622
MEDIUM
[@fastify/busboy] A multipart header parser accepts bare carriage returns or line feeds in Content-Disposition headers, allowing them to be passed to applications in filename and field name values, enabling filesystem pollution, log forging, or header injection attacks.
AIKIDO-2025-10564
MEDIUM
[@fastify/busboy] Improper parsing of quoted filename parameters allows attackers to bypass file extension validation by appending forbidden extensions outside closing quotes, potentially enabling malicious script execution or XSS attacks.
🤖 Remediation details

Fix critical and high-severity vulnerabilities in undici and @fastify/busboy

Both vulnerable packages (undici and @fastify/busboy) were transitive dependencies pulled in through the @actions/http-client chain. Fixes required bumping two direct dependencies in the root package.json (@actions/core, @actions/github) and adding a resolutions override for undici, with the lockfile (yarn.lock) updated accordingly.

undici

undici was a transitive dependency resolved at 5.29.0 via @actions/http-client@2.2.3, which was itself pulled in by @actions/core@^1.10.0 and @actions/github@^6.0.0. The required fix floor is 7.24.1, but no published version of @actions/http-client (up to the latest 4.0.1) declares a range that admits undici@7.x — the highest it reaches is ^6.23.0. Because no parent-chain bump could deliver undici@7.x, a resolutions entry ("undici": "^7.24.1") was added to the root package.json as a last resort, resolving undici to 7.29.0 across the tree. The direct dependencies @actions/core and @actions/github were also bumped (to ^2.0.0 and ^7.0.0 respectively) so that @actions/http-client resolves to 3.0.2, which declares undici@^6.23.0 — aligning the parent chain as closely as possible before the resolution takes effect.

@fastify/busboy

@fastify/busboy was a transitive dependency at 2.1.1, pulled in by undici@5.29.0 (which declared @fastify/busboy@^2.0.0). The fix was achieved indirectly: undici@7.x (resolved via the resolutions override described above) dropped its dependency on @fastify/busboy entirely, eliminating the vulnerable 2.1.1 instance from the tree. No separate resolution or parent bump was needed for @fastify/busboy itself; the only remaining lockfile entry for it is 3.2.2, a safe stale entry left from an intermediate install step.

Version changes

Package From To Why updated
undici 5.29.0 7.29.0 Direct CVE fix via resolutions override (^7.24.1); no parent chain could deliver 7.x
@fastify/busboy 2.1.1 3.2.2 Transitive CVE fix; vulnerable instance eliminated when undici was upgraded to 7.x (which dropped the dependency)
@actions/core ^1.10.0 ^2.0.0 Parent bump required to align @actions/http-client to 3.x range (which declares undici@^6.x)
@actions/github ^6.0.0 ^7.0.0 Parent bump required to align @actions/http-client to 3.x range (which declares undici@^6.x)
@actions/http-client 2.2.3 3.0.2 Transitive after parent bumps to @actions/core@^2.0.0 and @actions/github@^7.0.0

@aikido-autofix aikido-autofix Bot added aikido-autofix Label created by Aikido AutoFix Security Label created by Aikido AutoFix labels Aug 27, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

aikido-autofix Label created by Aikido AutoFix Security Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants