{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/undici--8.10.0--8.10.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-85152"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["undici (\u003e= 8.10.0, \u003c 8.10.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe undici HTTP client library is susceptible to cross-origin cache poisoning (CVE-2026-85152) due to an implementation flaw in how it constructs cache and deduplication keys within its interceptors. Specifically, the \u003ccode\u003einterceptors.cache()\u003c/code\u003e and \u003ccode\u003einterceptors.deduplicate()\u003c/code\u003e functions fail to incorporate the destination origin into the generated keys when a dispatcher lacks a single authoritative origin or when a request provides its own origin.\u003c/p\u003e\n\u003cp\u003eThis logic error enables an attacker who controls a response from a malicious or compromised origin to influence the cache entries for requests directed toward a different, trusted origin, provided the method, path, and relevant headers coincide. This vulnerability persists if a single cache store or interceptor instance is shared across multiple origins, facilitating cross-origin information disclosure or the poisoning of sensitive cached resources like JWKS (JSON Web Key Sets). The vulnerability was introduced in undici version 8.10.0 and affects versions 8.10.0 and 8.10.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eApplications that share an instance of \u003ccode\u003einterceptors.cache()\u003c/code\u003e or \u003ccode\u003einterceptors.deduplicate()\u003c/code\u003e across multiple, distinct origins are vulnerable. A successful exploit allows an attacker to perform persistent cache poisoning, which can result in the acceptance of attacker-signed tokens, leading to authentication bypass or unauthorized access. The scope of impact is contingent upon the application architecture and how extensively the vulnerable interceptor state is shared across network boundaries.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade undici to version 8.10.2 or later immediately to resolve the underlying cache key generation flaw.\u003c/li\u003e\n\u003cli\u003eAudit application code to identify where \u003ccode\u003einterceptors.cache()\u003c/code\u003e or \u003ccode\u003einterceptors.deduplicate()\u003c/code\u003e instances are instantiated.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not feasible, reconfigure the application to use separate cache stores and interceptor instances for every distinct origin, ensuring state isolation.\u003c/li\u003e\n\u003cli\u003eEnsure that \u003ccode\u003eAgent\u003c/code\u003e configurations, which are not impacted by this flaw, are used where feasible for origin-specific request handling.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T04:19:25Z","date_published":"2026-09-30T04:19:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-undici-cache-poisoning/","summary":"The undici library (v8.10.0-v8.10.1) is vulnerable to cross-origin cache poisoning via interceptors.cache() and interceptors.deduplicate() due to insufficient origin isolation in cache key generation, allowing attackers to serve malicious responses to trusted origins.","title":"Cross-Origin Cache Poisoning Vulnerability in undici","url":"https://feed.craftedsignal.io/briefs/2026-09-undici-cache-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - Undici (\u003e= 8.10.0, \u003c 8.10.2)","version":"https://jsonfeed.org/version/1.1"}