Source: node-undici Version: 8.5.0+dfsg+~cs3.2.0-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-undici. CVE-2026-16729[0]: | undici's setCookie function does not fully sanitize cookie | attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, | and from 8.0.0 up to before 8.9.0, a domain value is not checked for | semicolons and entries in the unparsed array are not sanitized, so | attacker-influenced input can inject additional cookie attributes. | For example, a domain value containing a semicolon can append | attributes such as SameSite, and an unparsed entry can inject | attributes such as HttpOnly, without the caller setting them. | Applications that pass user-controlled input to these fields, such | as multi-tenant or reverse-proxy servers that scope session cookies | to a tenant-supplied domain, can have SameSite CSRF protections | bypassed, or the Secure, HttpOnly, and SameSite attributes forced, | stripped, or overridden. The issue is fixed in undici 6.28.0, | 7.29.0, and 8.9.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-16729 https://www.cve.org/CVERecord?id=CVE-2026-16729 [1] https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm Please adjust the affected versions in the BTS as needed. Regards, Salvatore

