mediumCVSS 5.9Vulnerability

CVE-2026-9679

## Impact undici's cookie parser in `parseSetCookie` percent-decodes cookie values via `qsUnescape`, turning encoded sequences like `%0D%0A`, `%00`, `%3B`, and `%3D` into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a `Set-Cookie` header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary `Set-Cookie`, `Location`, or `Cache-Control` headers into the application's downstream response, enabling session fixation, open redirect, or cache poisoning. Affected applications are those that use undici's cookie parsing (`parseSetCookie`, `parseCookie`, `getSetCookies`) and forward the parsed cookie value into a response header. This was introduced in undici 7.0.0 via [#3789](https://github.com/nodejs/undici/pull/3789). ## Patches Upgrade to undici v6.27.0, v7.28.0 or v8.5.0. ## Workarounds If upgrade is not immediately possible, do not forward values returned by `parseSetCookie`/`parseCookie`/`getSetCookies` directly into response headers; sanitize the value first to strip or reject CR, LF, NUL, `;`, and `=` bytes.

Properties

severity
medium
summary
undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
epss_score
0.00257
cvss_score
5.9
ghsa_published
2026-06-19T14:21:30Z
source_url
https://github.com/advisories/GHSA-p88m-4jfj-68fv
ghsa_updated
2026-06-19T14:23:30Z
ghsa_id
GHSA-p88m-4jfj-68fv
cve_id
CVE-2026-9679
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.17618

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of CRLF Sequences ('CRLF Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/undici

AFFECTS (1)

[Software]npm/undici

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-9679 (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal