Permissive List of Allowed Inputs in undici - CVE-2026-11525

 

Permissive List of Allowed Inputs in undici - CVE-2026-11525

Published: June 17, 2026


Vulnerability identifier: #VU134752
CSH Severity: Low
CVSS v4 BT: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2026-11525
CWE-ID: CWE-183
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to weaken SameSite cookie policy enforcement.

The vulnerability exists due to permissive list of allowed inputs in the Set-Cookie header parser when parsing Set-Cookie headers from server responses. A remote attacker can send a specially crafted Set-Cookie header to weaken SameSite cookie policy enforcement.

The issue affects applications that forward or rely on the parsed sameSite attribute from server responses.


Affected software

undici

How to mitigate CVE-2026-11525

Install security update from vendor's website.

undici - addressed in versions 7.28.0, 8.5.0

External References

Related Security Bulletins