Permissive List of Allowed Inputs in undici - CVE-2026-11525
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to weaken SameSite cookie policy enforcement.
The vulnerability exists due to permissive list of allowed inputs in the Set-Cookie header parser when parsing Set-Cookie headers from server responses. A remote attacker can send a specially crafted Set-Cookie header to weaken SameSite cookie policy enforcement.
The issue affects applications that forward or rely on the parsed sameSite attribute from server responses.
Affected software
Netezza Appliance
Maximo Application Suite - Visual Inspection Component
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Fedora
nodejs22
nodejs24
How to mitigate CVE-2026-11525
Netezza Appliance - update to 1.0.2.0
Maximo Application Suite - Visual Inspection Component - addressed in versions 9.0.22, 9.1.19, 9.2.1
nodejs22 - update to 22.23.1-2.fc44
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Multiple vulnerabilities in IBM Maximo Application Suite - Visual Inspection Component
- Multiple vulnerabilities in IBM Netezza Appliance
- Fedora 44 update for nodejs24
- Fedora 44 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 8 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module