Permissive List of Allowed Inputs in undici - CVE-2026-11525
Published: June 17, 2026
undici
Detailed vulnerability description
The vulnerability allows a remote attacker to weaken SameSite cookie policy enforcement.
The vulnerability exists due to permissive list of allowed inputs in the Set-Cookie header parser when parsing Set-Cookie headers from server responses. A remote attacker can send a specially crafted Set-Cookie header to weaken SameSite cookie policy enforcement.
The issue affects applications that forward or rely on the parsed sameSite attribute from server responses.