PT-2026-86152 · Npm · Undici

·

CVE-2026-84933

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions undici versions 7.0.0 through 7.29.0 undici versions 8.0.0 through 8.10.1
Description The cache interceptor fails to handle the Set-Cookie response header, allowing it to be stored and re-served in shared cache mode. This occurs when a cacheable response contains a Set-Cookie header, such as those with public and max-age directives. Consequently, a cookie belonging to one user may be disclosed to another user, or an untrusted server could inject cookies into cached responses served to subsequent callers, violating the requirement that shared caches must not store cookies.
Recommendations Update undici versions 7.0.0 through 7.29.0 to version 7.29.1. Update undici versions 8.0.0 through 8.10.1 to version 8.10.2.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84933
GHSA-2JFJ-6HJV-FM6J

Affected Products

Undici