Skip to content

fix(sec): bump undici and discord.js#1190

Merged
TobiTenno merged 1 commit into
masterfrom
dependabot-npm_and_yarn-multi-d1cf14a530
Jul 24, 2026
Merged

fix(sec): bump undici and discord.js#1190
TobiTenno merged 1 commit into
masterfrom
dependabot-npm_and_yarn-multi-d1cf14a530

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps undici to 6.27.0 and updates ancestor dependency discord.js. These dependencies need to be updated together.

Updates undici from 6.24.1 to 6.27.0

Release notes

Sourced from undici's releases.

v6.27.0

⚠️ Security Release

This release line addresses 4 security advisories.

Action required: Upgrade to undici 6.27.0 or later.

npm install undici@^6.27.0

Note on patched version: the v6 fixes shipped in v6.27.0, not 6.26.0v6.26.0 contains only the chunked-EOF fix (#5308) and the version bump, none of the security fixes below.

The v6 line is not affected by the SOCKS5 advisories (GHSA-vmh5-mc38-953g, GHSA-hm92-r4w5-c3mj), the shared-cache disclosure (GHSA-pr7r-676h-xcf6), or the 8.x-only WebSocket regression (GHSA-38rv-x7px-6hhq).

Summary

Advisory CVE Severity (CVSS) Fixed in Fix commit
GHSA-vxpw-j846-p89q CVE-2026-12151 High (7.5) 6.27.0 b7f252e7
GHSA-p88m-4jfj-68fv CVE-2026-9679 Moderate (5.9) 6.27.0 25efa447
GHSA-g8m3-5g58-fq7m CVE-2026-11525 Low (3.7) 6.27.0 25efa447
GHSA-35p6-xmwp-9g52 CVE-2026-6733 Low (3.7) 6.27.0 f4c31d60

High severity

WebSocket DoS via fragment count bypass — CVE-2026-12151

GHSA-vxpw-j846-p89q · CWE-400, CWE-770 Fix: b7f252e7 Backport WebSocket maxPayloadSize fixes (#5423, backported to v6 in #5428)

A malicious WebSocket server can stream a large number of small or empty continuation frames. Undici enforced a limit on cumulative payload size but did not limit the number of fragments per message, leading to unbounded memory growth and denial of service. All releases from 6.17.0 onward are affected.

  • Affected: applications using new WebSocket(...) or WebSocketStream against untrusted endpoints.
  • Workaround: none — upgrade is required.

Moderate severity

HTTP header injection via Set-Cookie percent-decoding — CVE-2026-9679

... (truncated)

Commits

Updates discord.js from 14.26.4 to 14.27.0

Release notes

Sourced from discord.js's releases.

14.27.0

Bug Fixes

Documentation

Features

Refactor

Typings

  • WebhookMessageCreateOptions: Omit sharedClientTheme (b816b79)
  • Message: Specify rawData arg type (#11123) (c4531d4)
  • UserManager: Fix send() return type to Promise<Message> (#11337) (07c4127)

14.26.5

Bug Fixes

Changelog

Sourced from discord.js's changelog.

14.27.0 - (2026-07-15)

Bug Fixes

Documentation

Features

Refactor

Typings

  • WebhookMessageCreateOptions: Omit sharedClientTheme (b816b79)
  • Message: Specify rawData arg type (#11123) (c4531d4)
  • UserManager: Fix send() return type to Promise<Message> (#11337) (07c4127)

14.26.5 - (2026-07-10)

Bug Fixes

Commits

@dependabot dependabot Bot added Scope: Dependencies Pull requests that update a dependency file Type: Maintenance labels Jul 24, 2026
@TobiTenno

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [undici](https://github.com/nodejs/undici) to 6.27.0 and updates ancestor dependency [discord.js](https://github.com/discordjs/discord.js/tree/HEAD/packages/discord.js). These dependencies need to be updated together.


Updates `undici` from 6.24.1 to 6.27.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.24.1...v6.27.0)

Updates `discord.js` from 14.26.4 to 14.27.0
- [Release notes](https://github.com/discordjs/discord.js/releases)
- [Changelog](https://github.com/discordjs/discord.js/blob/14.27.0/packages/discord.js/CHANGELOG.md)
- [Commits](https://github.com/discordjs/discord.js/commits/14.27.0/packages/discord.js)

---
updated-dependencies:
- dependency-name: discord.js
  dependency-version: 14.27.0
  dependency-type: direct:production
- dependency-name: undici
  dependency-version: 6.27.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot-npm_and_yarn-multi-d1cf14a530 branch from 4f36579 to 765dbc0 Compare July 24, 2026 03:58
@TobiTenno TobiTenno changed the title ci: bump undici and discord.js fix(sec): bump undici and discord.js Jul 24, 2026
@TobiTenno
TobiTenno enabled auto-merge (squash) July 24, 2026 04:00
@TobiTenno
TobiTenno merged commit c8149ee into master Jul 24, 2026
5 checks passed
@TobiTenno
TobiTenno deleted the dependabot-npm_and_yarn-multi-d1cf14a530 branch July 24, 2026 04:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Scope: Dependencies Pull requests that update a dependency file Type: Maintenance

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant