Backport undici security bump to the 21.2.x LTS branch
envgap__angular__angular-cli-33449
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
41d34b5325ddbab53549c52c669a9cd335d88b4e- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
angular/angular-cli #33449 · read the original issue
### Command build ### Description Impact The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ### Describe the solution you'd like Upgrade undici from 7.24.4 to v7.28.0 or v8.5.0 or above. ### Describe alternatives you've considered _No response_ ###Precedent for backports Backports of this exact shape have already happened recently, including on this branch: https://github.com/angular/angular-cli/pull/32949 https://github.com/angular/angular-cli/issues/33420 https://github.com/angular/angular-cli/issues/32802
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]