Cross-Origin Cache Poisoning Vulnerability in undici
The undici library (v8.10.0-v8.10.1) is vulnerable to cross-origin cache poisoning via interceptors.cache() and interceptors.deduplicate() due to insufficient origin isolation in cache key generation, allowing attackers to serve malicious responses to trusted origins.
CVE search metadata
CVE search record: CVE-2026-85152. Severity: high. CVSS: 7.4. EPSS: 0.21%. KEV: no. Product: undici (>= 8.10.0, < 8.10.2). Brief: Cross-Origin Cache Poisoning Vulnerability in undici. Brief link: https://feed.craftedsignal.io/briefs/2026-09-undici-cache-poisoning/
The undici HTTP client library is susceptible to cross-origin cache poisoning (CVE-2026-85152) due to an implementation flaw in how it constructs cache and deduplication keys within its interceptors. Specifically, the interceptors.cache() and interceptors.deduplicate() functions fail to incorporate the destination origin into the generated keys when a dispatcher lacks a single authoritative origin or when a request provides its own origin.
This logic error enables an attacker who controls a response from a malicious or compromised origin to influence the cache entries for requests directed toward a different, trusted origin, provided the method, path, and relevant headers coincide. This vulnerability persists if a single cache store or interceptor instance is shared across multiple origins, facilitating cross-origin information disclosure or the poisoning of sensitive cached resources like JWKS (JSON Web Key Sets). The vulnerability was introduced in undici version 8.10.0 and affects versions 8.10.0 and 8.10.1.
Impact
Applications that share an instance of interceptors.cache() or interceptors.deduplicate() across multiple, distinct origins are vulnerable. A successful exploit allows an attacker to perform persistent cache poisoning, which can result in the acceptance of attacker-signed tokens, leading to authentication bypass or unauthorized access. The scope of impact is contingent upon the application architecture and how extensively the vulnerable interceptor state is shared across network boundaries.
Recommendation
- Upgrade undici to version 8.10.2 or later immediately to resolve the underlying cache key generation flaw.
- Audit application code to identify where
interceptors.cache()orinterceptors.deduplicate()instances are instantiated. - If immediate patching is not feasible, reconfigure the application to use separate cache stores and interceptor instances for every distinct origin, ensuring state isolation.
- Ensure that
Agentconfigurations, which are not impacted by this flaw, are used where feasible for origin-specific request handling.
Immediate actions
Upgrade undici to v8.10.2
Mitigations
Isolate cache store and interceptor instances per origin
CVE-2026-85152