GHSA-v3r7-h72x-cjcm

    Dashboard / Vulnerabilities / GHSA-v3r7-h72x-cjcm

    GHSA-v3r7-h72x-cjcm

    Published: 3 Aug 2026Last Modified: 4 Aug 2026

    Summary: undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

    Details: ## Impact The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array's loop only checks each entry contains `=` and does not sanitize values, so an entry like `X-Custom=val; HttpOnly` lands unchanged, injecting `HttpOnly` without the caller setting `cookie.httpOnly = true`. Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, `Secure` or `HttpOnly` forced or stripped, or the intended SameSite tier overridden. ## Patches Patched in undici v6.28.0, v7.29.0, and v8.9.0. ## Workarounds - Sanitize `domain` values against the RFC 1034 letter-digit-hyphen set before passing to `setCookie`. - Do not pass user-controlled data to the `unparsed` field.

    Affected packages

    Package

    Name: undici

    Purl: pkg:npm/undici

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -6.28.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High