CLEANSTART-2026-XL00241

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-XL00241.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-XL00241
Upstream
Published
2026-09-29T00:39:58Z
Modified
2026-09-30T00:45:19Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header
Details

Security vulnerability affects the langfuse package. undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header.

References

Affected packages

CleanStart / langfuse

Package

Name
langfuse

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.225.9-r1

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-XL00241.json"