CVE-2026-9678
Last modified
CVE-2026-9678 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored. In shared-cache mode, this allows a response containing one user's authenticated data to be served from cache to a subsequent caller, including an unauthenticated caller, when both requests resolve to the same cache key. Affected applications are those that explicitly enable the cache interceptor (interceptors.cache()) in shared mode, forward Authorization headers upstream, and receive cacheable responses with non-canonical qualified private or no-cache directives. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: If upgrade is not immediately possible, disable shared-cache mode for traffic that includes Authorization headers, avoid caching responses to authenticated requests, or add Vary: Authorization upstream.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored. In shared-cache mode, this allows a response containing one user's authenticated data to be served from cache to a subsequent caller, including an unauthenticated caller, when both requests resolve to the same cache key. Affected applications are those that explicitly enable the cache interceptor (interceptors.cache()) in shared mode, forward Authorization headers upstream, and receive cacheable responses with non-canonical qualified private or no-cache directives. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: If upgrade is not immediately possible, disable shared-cache mode for traffic that includes Authorization headers, avoid caching responses to authenticated requests, or add Vary: Authorization upstream.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Undici | >= 7.0.0, < 7.28.0 |
| Nodejs | Undici | >= 8.0.0, < 8.5.0 |
References
- https://cna.openjsf.org/security-advisories.htmlVendor Advisory
- https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9678?
How severe is CVE-2026-9678?
How do I fix CVE-2026-9678?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9669bz2.BZ2Decompressor objects could be reused after a decompre…8.2
- CVE-2026-9673Versions of the package json-2-csv from 3.15.0 and before 5.…6.8
- CVE-2026-9674A cross-site request forgery (CSRF) vulnerability in Jenkins…4.3
- CVE-2026-9675Impact: The undici WebSocket client enforces maxPayloadSize …7.5
- CVE-2026-9676The F4 Post Tree WordPress plugin before 2.0.5 does not perf…4.3
- CVE-2026-9677The Shariff for WordPress Shariff for WordPress plugin throu…4.8
- CVE-2026-9679Impact: undici's cookie parser in parseSetCookie percent-dec…5.9
- CVE-2026-9680Improper exposure of the MCP server in alibabacloud-rds-open…5.8
- CVE-2026-9689A flaw was found in Keycloak, an open-source identity and ac…4.2
- CVE-2026-9690Unauthenticated Arbitrary File Download in WP Media folder A…7.5
- CVE-2026-9691Unauthenticated PHP Object Injection in Integration for Acti…9.8
- CVE-2026-9692Mojolicious::Sessions::Storable versions through 0.05 for Pe…5.3
Are you affected by CVE-2026-9678?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
