CVE-2026-85152

Description

A flaw was found in undici. When the cache or deduplicate interceptor is directly composed onto a Client or Pool, the destination origin is omitted from cache and request-deduplication keys. This allows a remote attacker to perform cross-origin cache poisoning, leading to information disclosure and potentially a full authentication bypass. An attacker could exploit this by having a trusted origin accept a malicious token, without contacting the legitimate trusted origin.

Statement

This flaw is present in the undici HTTP client library used by Node.js. When an application composes undici's Cache or Deduplicate interceptor directly onto a Client or Pool object (rather than onto an Agent), the library's internal cache and in-flight-request deduplication keys omit the destination origin. As a result, a cached or in-flight response captured for one upstream origin can be returned for a request intended for a different, trusted origin whenever the method, path, and relevant headers match. In the most severe demonstrated scenario, this allowed an attacker-controlled JWT to be accepted by the application as though it had been validated against a legitimate, trusted issuer, without that issuer ever being contacted — resulting in a full authentication bypass. Exploitation requires that the affected application attach the Cache or Deduplicate interceptor directly to a Client/Pool — the default Agent-based dispatch path is not affected, since Agent already carries the origin in its dispatch options — and that an attacker can influence or collide with the cache/deduplication key for at least one origin the application communicates with.).

Mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible to undici 8.10.2 or later.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.4N/A7.4
Attack VectorNetworkN/ANetwork
Attack ComplexityHighN/AHigh
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactNoneN/ANone

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Understanding the Weakness (CWE)

Access Control,Other

Technical Impact: Gain Privileges or Assume Identity; Varies by Context

An attacker can access any functionality that is inadvertently accessible to the source.

Frequently Asked Questions

Want to get errata notifications? Sign up here.