CVE-2026-84933 affects multiple packages. undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. See references for individual vulnerability details.