CLEANSTART-2026-WF83239

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-WF83239.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-WF83239
Upstream
Published
2026-10-10T00:47:54Z
Modified
2026-10-10T01:00:21Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header
Details

Security vulnerability affects the n8n package. undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header.

References

Affected packages

CleanStart / n8n

Package

Name
n8n
Purl
pkg:apk/cleanstart/n8n

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.28.0-r5

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-WF83239.json"