Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14643— undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

CVSS 5.9 · Medium EPSS 0.23% · P14

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 4

VendorProductVersion RangeStatus
undiciundici7.0.0< 7.29.0affected
7.29.0unaffected
8.0.0< 8.9.0affected
8.9.0unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-14643

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
Source: CVE Program / CVE List V5
Vulnerability Description
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
解释冲突
Source: CVE Program / CVE List V5
Vulnerability Title
undici 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
undici undici是undici组织的一个HTTP客户端库。 undici 7.0.0版本至7.29.0之前版本和8.0.0版本至8.9.0之前版本存在安全漏洞,该漏洞源于缓存拦截器错误处理了限定no-cache或private Cache-Control指令等号周围的可选空格,可能导致在共享缓存模式下用户认证数据被后续未授权调用者访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
undiciundici 7.0.0 ~ 7.29.0 -

II. Public POCs for CVE-2026-14643

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14643

登录查看更多情报信息。

Vendor Advisories for CVE-2026-14643 (1)

Same Patch Batch · undici · 2026-07-29 · 5 CVEs total

CVE-2026-136977.4 HIGHundici vulnerable to cross-user information disclosure and parse-time crash via degenerate
CVE-2026-167294.8 MEDIUMundici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCoo
CVE-2026-167284.8 MEDIUMundici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-151574.2 MEDIUMundici vulnerable to CRLF Injection via blob-like body 'type' property

IV. Related Vulnerabilities

V. Comments for CVE-2026-14643

No comments yet


Leave a comment