close
Skip to content

[pull] main from nodejs:main#342

Merged
pull[bot] merged 2 commits into
Reality2byte:mainfrom
nodejs:main
Jul 22, 2026
Merged

[pull] main from nodejs:main#342
pull[bot] merged 2 commits into
Reality2byte:mainfrom
nodejs:main

Conversation

@pull

@pull pull Bot commented Jul 22, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by Image pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

mcollina and others added 2 commits July 22, 2026 08:26
Functions bypassed the object guard in processHeader() and were
coerced via template literals without isValidHeaderValue(), allowing
CRLF injection when toString/Symbol.toPrimitive returned embedded
newlines. Validate after coercion on both scalar and array paths.

Signed-off-by: Matteo Collina <hello@matteocollina.com>
* fix: handle frozen globalThis in setGlobalDispatcher

When Object.freeze(globalThis) is called before undici globals are accessed,
setGlobalDispatcher would throw TypeError because it cannot extend globalThis.

This fix wraps the Object.defineProperty calls in try/catch. When globalThis
is not extensible (frozen), the dispatcher is stored in a module-level
fallback variable instead. getGlobalDispatcher is updated to return the
fallback dispatcher when the globalThis property is not available.

This allows undici to work correctly even when globalThis has been frozen,
which is recommended by Node.js security best practices (CWE-349).

Fixes issue where Object.freeze(globalThis) breaks undici access.

* test: add unit test for frozen globalThis in setGlobalDispatcher

Add comprehensive test coverage for the frozen globalThis fix. Tests verify:
1. setGlobalDispatcher does not throw when globalThis is frozen
2. getGlobalDispatcher continues to return a valid dispatcher
3. The fallback mechanism works correctly when globalThis is not extensible

This addresses the review feedback from mcollina requesting tests.

* test: improve frozen globalThis test coverage

Add comprehensive test cases to ensure all code paths in the frozen globalThis
fix are exercised. Tests verify:
1. setGlobalDispatcher does not throw when globalThis is frozen
2. getGlobalDispatcher returns a valid dispatcher
3. Fallback dispatcher persists across multiple calls

This addresses review feedback requesting tests.
@pull pull Bot locked and limited conversation to collaborators Jul 22, 2026
@pull pull Bot added the ⤵️ pull label Jul 22, 2026
@pull
pull Bot merged commit a0922b0 into Reality2byte:main Jul 22, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants