CVE-2026-9679
Last modified
CVE-2026-9679 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary Set-Cookie, Location, or Cache-Control headers into the application's downstream response, enabling session fixation, open redirect, or cache poisoning. Affected applications are those that use undici's cookie parsing (parseSetCookie, parseCookie, getSetCookies) and forward the parsed cookie value into a response header. This was introduced in undici 7.0.0 via PR #3789. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: If upgrade is not immediately possible, do not forward values returned by parseSetCookie/parseCookie/getSetCookies directly into response headers; sanitize the value first to strip or reject CR, LF, NUL, ;, and = bytes.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary Set-Cookie, Location, or Cache-Control headers into the application's downstream response, enabling session fixation, open redirect, or cache poisoning. Affected applications are those that use undici's cookie parsing (parseSetCookie, parseCookie, getSetCookies) and forward the parsed cookie value into a response header. This was introduced in undici 7.0.0 via PR #3789. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: If upgrade is not immediately possible, do not forward values returned by parseSetCookie/parseCookie/getSetCookies directly into response headers; sanitize the value first to strip or reject CR, LF, NUL, ;, and = bytes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Undici | < 6.27.0 |
| Nodejs | Undici | >= 7.0.0, < 7.28.0 |
| Nodejs | Undici | >= 8.0.0, < 8.5.0 |
References
- https://cna.openjsf.org/security-advisories.htmlVendor Advisory
- https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fvVendor Advisory, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-9679?
How severe is CVE-2026-9679?
How do I fix CVE-2026-9679?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-96772A security flaw has been discovered in Intelliants Subrion C…5.3
- CVE-2026-96773A weakness has been identified in Intelliants Subrion CMS up…4.3
- CVE-2026-96774A vulnerability was found in SPON Communications IP Network …5.3
- CVE-2026-96775MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_A…8.8
- CVE-2026-96777A vulnerability was determined in Forma LMS up to 4.1.43. Th…6.3
- CVE-2026-9678Impact: Undici's cache interceptor incorrectly classifies so…5.9
- CVE-2026-96795Horilla is an HR and CRM software. Prior to 2.0.0, HorillaLi…8.8
- CVE-2026-9680Improper exposure of the MCP server in alibabacloud-rds-open…5.8
- CVE-2026-96803A vulnerability was identified in java110 MicroCommunity up …7.3
- CVE-2026-96804MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits …8.8
- CVE-2026-96807In Flatpak before 1.18.1, a malicious sandboxed app can repl…4
- CVE-2026-96808In Flatpak before 1.18.1, the revokefs writer, used by the f…7.4
Are you affected by CVE-2026-9679?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
