SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84933

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability arises from undici's cache interceptor failing to properly handle the Set-Cookie response header, allowing cached responses containing sensitive cookies to be served to unintended users. This can lead to cookie disclosure and potential session hijacking, particularly in shared cache environments. Organizations using affected undici versions should prioritize upgrading to versions 7.29.1 or 8.10.2 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84933
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

Related CVEs

Other vulnerabilities affecting the same vendor(s)