Source: node-undici
Version: 8.5.0+dfsg+~cs3.2.0-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-undici.

CVE-2026-16729[0]:
| undici's setCookie function does not fully sanitize cookie
| attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0,
| and from 8.0.0 up to before 8.9.0, a domain value is not checked for
| semicolons and entries in the unparsed array are not sanitized, so
| attacker-influenced input can inject additional cookie attributes.
| For example, a domain value containing a semicolon can append
| attributes such as SameSite, and an unparsed entry can inject
| attributes such as HttpOnly, without the caller setting them.
| Applications that pass user-controlled input to these fields, such
| as multi-tenant or reverse-proxy servers that scope session cookies
| to a tenant-supplied domain, can have SameSite CSRF protections
| bypassed, or the Secure, HttpOnly, and SameSite attributes forced,
| stripped, or overridden. The issue is fixed in undici 6.28.0,
| 7.29.0, and 8.9.0.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16729
    https://www.cve.org/CVERecord?id=CVE-2026-16729
[1] https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to