{"id":"GHSA-8436-99hf-9mmv","summary":"undici vulnerable to caching and replay of unsafe HTTP method responses","details":"### Impact\n\nundici's `interceptors.cache()` documents that it caches only safe HTTP methods. However, its internal skip-list is built by subtracting the configured methods from the safe-methods set, so an unsafe method (`POST`, `PUT`, `PATCH`, `DELETE`) never lands in the skip-list and is looked up against the cache store. Combined with the storage gate (`canCacheResponse`) having no method check, a heuristically-cacheable response (for example a `404`) with an explicit `Cache-Control: max-age=...` to an unsafe method is stored and replayed on a subsequent identical request. The application's state-changing request never reaches the origin, and undici serves a fabricated response from the cache instead. This occurs with the default configuration (`methods: ['GET']`), which the public API does not allow widening to unsafe methods, so no application misuse is required; an untrusted origin can trigger it purely through its own response headers.\n\n### Patches\n\nUpgrade to `7.29.1` or `8.10.2`. The cache interceptor no longer reads from or writes to the cache for unsafe HTTP methods, while still invalidating existing cache entries on successful unsafe requests.\n\n### Workarounds\n\nNone.","aliases":["CVE-2026-85008"],"modified":"2026-09-29T18:28:12.530229215Z","published":"2026-09-29T18:16:28Z","database_specific":{"github_reviewed_at":"2026-09-29T18:16:28Z","nvd_published_at":"2026-09-04T17:17:02Z","cwe_ids":["CWE-345"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85008"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/2be07bf97b3022e0324142d31f99f6e019d815e3"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/b61d9432bac7caac51273ad209862e4c0bf935ae"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/nodejs/undici"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v7.29.1"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v8.10.2"}],"affected":[{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.29.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-8436-99hf-9mmv/GHSA-8436-99hf-9mmv.json"}},{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-8436-99hf-9mmv/GHSA-8436-99hf-9mmv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}