SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14643

MEDIUM · CVSS 5.9 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The vulnerability arises in undici's cache interceptor, which improperly handles optional whitespace around the equals sign in Cache-Control directives, leading to potential exposure of authenticated user data in shared-cache scenarios. This flaw allows cached responses to be served to unauthorized users, posing a risk to applications that utilize the cache interceptor in shared mode and forward Authorization headers. Organizations using affected versions of undici should prioritize patching to versions 7.29.0 or 8.9.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14643
Severity
MEDIUM
CVSS
5.9
EPSS
0.30%

Original NVD Description

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)