Περιγραφή
undici-s cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer-s error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.
- Δημοσίευση
- 2026-07-29 17:16:50
- Επηρεαζόμενες εκδόσεις
- <7.29.0, <8.9.0
- Τύπος
- Βιβλιοθήκη
- Τελευταία τροποποίηση
- 2026-08-04 14:17:59
- Διάνυσμα
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H