PT-2026-86152 · Npm · Undici
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
undici versions 7.0.0 through 7.29.0
undici versions 8.0.0 through 8.10.1
Description
The cache interceptor fails to handle the
Set-Cookie response header, allowing it to be stored and re-served in shared cache mode. This occurs when a cacheable response contains a Set-Cookie header, such as those with public and max-age directives. Consequently, a cookie belonging to one user may be disclosed to another user, or an untrusted server could inject cookies into cached responses served to subsequent callers, violating the requirement that shared caches must not store cookies.Recommendations
Update undici versions 7.0.0 through 7.29.0 to version 7.29.1.
Update undici versions 8.0.0 through 8.10.1 to version 8.10.2.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undici