Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85152

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.

A flaw was found in undici. When the cache or deduplicate interceptor is directly composed onto a Client or Pool, the destination origin is omitted from cache and request-deduplication keys. This allows a remote attacker to perform cross-origin cache poisoning, leading to information disclosure and potentially a full authentication bypass. An attacker could exploit this by having a trusted origin accept a malicious token, without contacting the legitimate trusted origin.

Отчет

This flaw is present in the undici HTTP client library used by Node.js. When an application composes undici's Cache or Deduplicate interceptor directly onto a Client or Pool object (rather than onto an Agent), the library's internal cache and in-flight-request deduplication keys omit the destination origin. As a result, a cached or in-flight response captured for one upstream origin can be returned for a request intended for a different, trusted origin whenever the method, path, and relevant headers match. In the most severe demonstrated scenario, this allowed an attacker-controlled JWT to be accepted by the application as though it had been validated against a legitimate, trusted issuer, without that issuer ever being contacted — resulting in a full authentication bypass. Exploitation requires that the affected application attach the Cache or Deduplicate interceptor directly to a Client/Pool — the default Agent-based dispatch path is not affected, since Agent already carries the origin in its dispatch options — and that an attacker can influence or collide with the cache/deduplication key for at least one origin the application communicates with.).

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible to undici 8.10.2 or later.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence/vulnerability-analysis-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-pf5-rhel9Affected
OpenShift Pipelinesopenshift-pipelines/pipelines-console-plugin-rhel9Affected
Red Hat AMQ Broker 7amq-broker-bin.zipNot affected
Red Hat AMQ Broker 7amq-broker-maven-repository.zipAffected
Red Hat Ansible Automation Platform 2automation-platform-uiNot affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitAffected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backendNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backendNot affected
Red Hat Developer Hubrhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-lokiNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2528717undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation

EPSS

Процентиль: 7%
0.00173
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
9 дней назад

(undici 8.10.0 omits the destination origin from the cache and request- ...)

CVSS3: 7.4
nvd
12 дней назад

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.

CVSS3: 7.4
debian
12 дней назад

undici 8.10.0 omits the destination origin from the cache and request- ...

EPSS

Процентиль: 7%
0.00173
Низкий

7.4 High

CVSS3

Уязвимость CVE-2026-85152