GHSA-p88m-4jfj-68fv

    Dashboard / Vulnerabilities / GHSA-p88m-4jfj-68fv

    GHSA-p88m-4jfj-68fv

    Published: 19 Jun 2026Last Modified: 10 Sept 2026
    Aliases:

    Summary: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

    Details: ## Impact undici's cookie parser in `parseSetCookie` percent-decodes cookie values via `qsUnescape`, turning encoded sequences like `%0D%0A`, `%00`, `%3B`, and `%3D` into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a `Set-Cookie` header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary `Set-Cookie`, `Location`, or `Cache-Control` headers into the application's downstream response, enabling session fixation, open redirect, or cache poisoning. Affected applications are those that use undici's cookie parsing (`parseSetCookie`, `parseCookie`, `getSetCookies`) and forward the parsed cookie value into a response header. This was introduced in undici 7.0.0 via [#3789](https://github.com/nodejs/undici/pull/3789). ## Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ## Workarounds If upgrade is not immediately possible, do not forward values returned by `parseSetCookie`/`parseCookie`/`getSetCookies` directly into response headers; sanitize the value first to strip or reject CR, LF, NUL, `;`, and `=` bytes.

    Affected packages

    Package

    Name: undici

    Purl: pkg:npm/undici

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -6.27.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-p88m-4jfj-68fv | CVE-DB