GHSA-vp8m-p9jh-q5pm

Suggest an improvement
Source
https://github.com/advisories/GHSA-vp8m-p9jh-q5pm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vp8m-p9jh-q5pm/GHSA-vp8m-p9jh-q5pm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vp8m-p9jh-q5pm
Aliases
Published
2026-09-29T18:15:13Z
Modified
2026-09-29T18:28:14Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
Details

Impact

When interceptors.cache() or interceptors.deduplicate() is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own origin, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.

An attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.

Applications that share interceptors.cache() or interceptors.deduplicate() state across origins are affected. An Agent is not affected, because its dispatch options include the request origin.

This was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.

Patches

Upgrade to undici v8.10.2.

Workarounds

Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.

Database specific
{
    "cwe_ids":  [
        "CWE-346"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T18:15:13Z",
    "nvd_published_at":  "2026-09-04T17:17:02Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / undici

Package

Affected ranges

Type
SEMVER
Events
Introduced
8.10.0
Fixed
8.10.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vp8m-p9jh-q5pm/GHSA-vp8m-p9jh-q5pm.json"