CVE-2026-16729

EUVD-2026-50416
undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie attributes. For example, a domain value containing a semicolon can append attributes such as SameSite, and an unparsed entry can inject attributes such as HttpOnly, without the caller setting them. Applications that pass user-controlled input to these fields, such as multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, or the Secure, HttpOnly, and SameSite attributes forced, stripped, or overridden. The issue is fixed in undici 6.28.0, 7.29.0, and 8.9.0.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.79%
Affected Products (NVD)
VendorProductVersion
nodejsundici
𝑥
< 6.28.0
nodejsundici
7.0.0 ≤
𝑥
< 7.29.0
nodejsundici
8.0.0 ≤
𝑥
< 8.9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-undici
bookworm
postponed
bookworm (security)
vulnerable
forky
8.9.0+dfsg+~cs3.2.0-1
fixed
sid
8.10.2+dfsg+~cs3.2.2-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-undici
jammy
dne
noble
needs-triage
resolute
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs20
suse enterprise sap 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise sap 15 SP6
20.20.2-150600.3.21.1
fixed
suse enterprise server 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.21.1
fixed
nodejs20-devel
suse enterprise sap 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise sap 15 SP6
20.20.2-150600.3.21.1
fixed
suse enterprise server 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.21.1
fixed
nodejs20-docs
suse enterprise sap 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise sap 15 SP6
20.20.2-150600.3.21.1
fixed
suse enterprise server 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.21.1
fixed
npm20
suse enterprise sap 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise sap 15 SP6
20.20.2-150600.3.21.1
fixed
suse enterprise server 15 SP5
20.20.2-150500.11.30.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.21.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
nodejs22
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-debuginfo
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-debugsource
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-devel
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-docs
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-full-i18n
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-libs
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-libs-debuginfo
Amazon Linux 2023
1:22.23.2-1.amzn2023.0.2
fixed
nodejs22-npm
Amazon Linux 2023
1:10.9.8-1.22.23.2.1.amzn2023.0.2
fixed
nodejs24
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-debuginfo
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-debugsource
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-devel
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-docs
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-full-i18n
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-libs
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-libs-debuginfo
Amazon Linux 2023
1:24.18.1-1.amzn2023.0.2
fixed
nodejs24-npm
Amazon Linux 2023
1:11.16.0-1.24.18.1.1.amzn2023.0.2
fixed
v8-12.4-devel
Amazon Linux 2023
3:12.4.254.21-1.22.23.2.1.amzn2023.0.2
fixed
v8-13.6-devel
Amazon Linux 2023
3:13.6.233.17-1.24.18.1.1.amzn2023.0.2
fixed