Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-13697— undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

Quick assessment

Affected
undici undici
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

undici undici是undici组织的一个HTTP客户端库。 undici 7.0.0版本至7.29.0之前版本和8.0.0版本至8.9.0之前版本存在安全漏洞,该漏洞源于缓存拦截器错误处理畸形的Cache-Control私有指令,可能导致私有响应被共享缓存存储并泄露给不同调用者,以及Cache-Control头组合问题导致未捕获的类型错误,可能终止进程。

CVSS 7.4 · High EPSS 0.57% · P45

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 4

VendorProduct Version RangeStatus
undici undici 7.0.0< 7.29.0 affected
7.29.0 unaffected
8.0.0< 8.9.0 affected
8.9.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13697

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
Source: CVE Program / CVE List V5
Vulnerability Description
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer's error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
undici 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
undici undici是undici组织的一个HTTP客户端库。 undici 7.0.0版本至7.29.0之前版本和8.0.0版本至8.9.0之前版本存在安全漏洞,该漏洞源于缓存拦截器错误处理畸形的Cache-Control私有指令,可能导致私有响应被共享缓存存储并泄露给不同调用者,以及Cache-Control头组合问题导致未捕获的类型错误,可能终止进程。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
undici undici 7.0.0 ~ 7.29.0 -

II. Public POCs for CVE-2026-13697

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 10654 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-13697

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-13697 (1)

Same Patch Batch · undici · 2026-07-29 · 5 CVEs total

CVE-2026-14643 5.9 MEDIUM undici vulnerable to cross-user information disclosure via whitespace around equals in Cac
CVE-2026-16729 4.8 MEDIUM undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCoo
CVE-2026-16728 4.8 MEDIUM undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-15157 4.2 MEDIUM undici vulnerable to CRLF Injection via blob-like body 'type' property

IV. Related Vulnerabilities

V. Comments for CVE-2026-13697

No comments yet


Leave a comment