THREAT OPS › Threat News › [GHSA] GHSA-8xcm-r25x-g524 (medium) — undici vulnerable to downstream response desynchronization via retry interceptor
[GHSA] GHSA-8xcm-r25x-g524 (medium) — undici vulnerable to downstream response desynchronization via retry interceptor
GHSA-8xcm-r25x-g524 Severity: medium CVE: CVE-2026-16728
undici vulnerable to downstream response desynchronization via retry interceptor
### Impact
Undici's `interceptors.retry()` can deliver a response whose body length does not match the `Content-Length` header exposed to the application after a retry or resume of a partial response. Applications that use `interceptors.retry()` and forward u
Indicators of compromise
- CVE-2026-16728cve
Original source: https://github.com/advisories/GHSA-8xcm-r25x-g524