Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14643

Опубликовано: 29 июл. 2026
Источник: redhat
CVSS3: 5.9

Описание

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.

A flaw was found in undici. The cache interceptor in undici improperly handles optional whitespace around the equals sign in no-cache or private Cache-Control directives. This vulnerability allows an attacker to bypass cache restrictions, leading to cross-user information disclosure. Specifically, authenticated user data can be inadvertently served from the cache to a different, potentially unauthenticated, user if both requests resolve to the same cache key.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened ImagesjaegerNot affected
Red Hat Hardened Imagesnodejs25Will not fix
Red Hat Hardened Imagesprometheus3.13Not affected
Red Hat Hardened ImagesrustNot affected
Red Hat Hardened Imagesnodejs26-main-26.5.1-1.5.hum1FixedRHSA-2026:4827329.07.2026
Red Hat Hardened Imagesnodejs24-main-24.18.1-0.1.hum1FixedRHSA-2026:4853730.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-524
https://bugzilla.redhat.com/show_bug.cgi?id=2508676undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
20 дней назад

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.

CVSS3: 5.9
nvd
20 дней назад

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.

CVSS3: 5.9
debian
20 дней назад

undici's cache interceptor mishandles optional whitespace placed aroun ...

CVSS3: 5.9
github
15 дней назад

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

5.9 Medium

CVSS3