๐Ÿ” CVE Alert

CVE-2026-16729

MEDIUM 4.8

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.

CWE CWE-74
Vendor undici
Product undici
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for undici undici

Be the first to know when new medium vulnerabilities affecting undici undici are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

undici / undici
0 < 6.28.0 7.0.0 < 7.29.0 8.0.0 < 8.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm cna.openjsf.org: https://cna.openjsf.org/security-advisories.html

Credits

๐Ÿ” Zelys-DFKH mcollina UlisesGascon