Количество 17
Количество 17
GHSA-g8m3-5g58-fq7m
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-11525
Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie...
CVE-2026-11525
Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie...
CVE-2026-11525
Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cooki
CVE-2026-11525
undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
CVE-2026-11525
Impact: When undici parses a Set-Cookie header, it accepts any SameSit ...
RLSA-2026:35892
Important: nodejs:22 security, bug fix, and enhancement update
RLSA-2026:35842
Important: nodejs22 security, bug fix, and enhancement update
ELSA-2026-35892
ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT)
RLSA-2026:35891
Important: nodejs:24 security, bug fix, and enhancement update
RLSA-2026:35841
Important: nodejs24 security, bug fix, and enhancement update
ELSA-2026-35891
ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:2695-1
Security update for nodejs22
SUSE-SU-2026:2647-1
Security update for nodejs22
openSUSE-SU-2026:21236-1
Security update for nodejs24
SUSE-SU-2026:2633-1
Security update for nodejs24
openSUSE-SU-2026:21058-1
Security update for nodejs22
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-g8m3-5g58-fq7m undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching | CVSS3: 3.7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-11525 Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie... | CVSS3: 3.7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-11525 Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie... | CVSS3: 3.7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-11525 Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cooki | CVSS3: 3.7 | 0% Низкий | около 1 месяца назад | |
CVE-2026-11525 undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching | 0% Низкий | около 1 месяца назад | ||
CVE-2026-11525 Impact: When undici parses a Set-Cookie header, it accepts any SameSit ... | CVSS3: 3.7 | 0% Низкий | около 1 месяца назад | |
RLSA-2026:35892 Important: nodejs:22 security, bug fix, and enhancement update | 24 дня назад | |||
RLSA-2026:35842 Important: nodejs22 security, bug fix, and enhancement update | 23 дня назад | |||
ELSA-2026-35892 ELSA-2026-35892: nodejs:22 security, bug fix, and enhancement update (IMPORTANT) | 23 дня назад | |||
RLSA-2026:35891 Important: nodejs:24 security, bug fix, and enhancement update | 24 дня назад | |||
RLSA-2026:35841 Important: nodejs24 security, bug fix, and enhancement update | 21 день назад | |||
ELSA-2026-35891 ELSA-2026-35891: nodejs:24 security, bug fix, and enhancement update (IMPORTANT) | 24 дня назад | |||
SUSE-SU-2026:2695-1 Security update for nodejs22 | около 1 месяца назад | |||
SUSE-SU-2026:2647-1 Security update for nodejs22 | около 1 месяца назад | |||
openSUSE-SU-2026:21236-1 Security update for nodejs24 | 24 дня назад | |||
SUSE-SU-2026:2633-1 Security update for nodejs24 | около 1 месяца назад | |||
openSUSE-SU-2026:21058-1 Security update for nodejs22 | около 1 месяца назад |
Уязвимостей на страницу