GHSA-VP8M-P9JH-Q5PM

Vulnerability from github – Published: 2026-09-29 18:15 – Updated: 2026-09-29 18:15
VLAI
Summary
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
Details

Impact

When interceptors.cache() or interceptors.deduplicate() is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own origin, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.

An attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.

Applications that share interceptors.cache() or interceptors.deduplicate() state across origins are affected. An Agent is not affected, because its dispatch options include the request origin.

This was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.

Patches

Upgrade to undici v8.10.2.

Workarounds

Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "undici"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "8.10.0"
            },
            {
              "fixed": "8.10.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-85152"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-346"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-29T18:15:13Z",
    "nvd_published_at": "2026-09-04T17:17:02Z",
    "severity": "HIGH"
  },
  "details": "## Impact\n\nWhen `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.\n\nAn attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.\n\nApplications that share `interceptors.cache()` or `interceptors.deduplicate()` state across origins are affected. An `Agent` is not affected, because its dispatch options include the request origin.\n\nThis was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.\n\n## Patches\n\nUpgrade to undici v8.10.2.\n\n## Workarounds\n\nUse a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.",
  "id": "GHSA-vp8m-p9jh-q5pm",
  "modified": "2026-09-29T18:15:13Z",
  "published": "2026-09-29T18:15:13Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85152"
    },
    {
      "type": "WEB",
      "url": "https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80"
    },
    {
      "type": "WEB",
      "url": "https://cna.openjsf.org/security-advisories.html"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/nodejs/undici"
    },
    {
      "type": "WEB",
      "url": "https://github.com/nodejs/undici/releases/tag/v8.10.2"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…