{"id":"GHSA-vp8m-p9jh-q5pm","summary":"undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors","details":"## Impact\n\nWhen `interceptors.cache()` or `interceptors.deduplicate()` is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own `origin`, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.\n\nAn attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.\n\nApplications that share `interceptors.cache()` or `interceptors.deduplicate()` state across origins are affected. An `Agent` is not affected, because its dispatch options include the request origin.\n\nThis was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.\n\n## Patches\n\nUpgrade to undici v8.10.2.\n\n## Workarounds\n\nUse a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.","aliases":["CVE-2026-85152"],"modified":"2026-09-29T18:28:14.852486023Z","published":"2026-09-29T18:15:13Z","database_specific":{"nvd_published_at":"2026-09-04T17:17:02Z","cwe_ids":["CWE-346"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-29T18:15:13Z"},"references":[{"type":"WEB","url":"https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85152"},{"type":"WEB","url":"https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80"},{"type":"WEB","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"PACKAGE","url":"https://github.com/nodejs/undici"},{"type":"WEB","url":"https://github.com/nodejs/undici/releases/tag/v8.10.2"}],"affected":[{"package":{"name":"undici","ecosystem":"npm","purl":"pkg:npm/undici"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.10.0"},{"fixed":"8.10.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vp8m-p9jh-q5pm/GHSA-vp8m-p9jh-q5pm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}