Vulnerability GHSA-v3r7-h72x-cjcm

Medium Risk
MEDIUM RISK
CVSS Score: 4.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 month ago
August 03, 2026 at 07:30 PM UTC
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
0.1.0 - 6.27.0 and 7.0.0 - 7.28.0 and 8.0.0 - 8.8.0
0.1.0 - 6.27.0 and 7.0.0 - 7.28.0 and 8.0.0 - 8.8.0

Summary

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

Details

Impact

The setCookie function has two attribute injection paths. validateCookieDomain does not reject semicolons (validateCookiePath already does at 0x3B), so a domain value like example.com; SameSite=None lands verbatim as Domain=example.com; SameSite=None. The unparsed array's loop only checks each entry contains = and does not sanitize values, so an entry like X-Custom=val; HttpOnly lands unchanged, injecting HttpOnly without the caller setting cookie.httpOnly = true.

Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, Secure or HttpOnly forced or stripped, or the intended SameSite tier overridden.

Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0.

Workarounds

  • Sanitize domain values against the RFC 1034 letter-digit-hyphen set before passing to setCookie.
  • Do not pass user-controlled data to the unparsed field.

Impacted packages

Timeline

Published
1 month ago
August 03, 2026 at 07:30 PM UTC
Fixed (8.9.0)
2 months ago
July 24, 2026 at 12:32 PM UTC
Fixed (7.29.0)
2 months ago
July 24, 2026 at 12:52 PM UTC
Fixed (6.28.0)
2 months ago
July 24, 2026 at 12:55 PM UTC
Last Modified
19 days ago
September 10, 2026 at 03:51 AM UTC