Use of cache containing sensitive information in undici - CVE-2026-9678
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of cache containing sensitive information in the cache interceptor when processing responses with whitespace-padded qualified private or no-cache directives in the Cache-Control header. A remote attacker can send requests that resolve to the same cache key to disclose sensitive information.
Only applications that explicitly enable interceptors.cache() in shared-cache mode, forward Authorization headers upstream, and receive cacheable responses with non-canonical qualified directives are vulnerable.
Affected software
Netezza Appliance
Netezza Appliance - Cyclops
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Fedora
IBM Maximo Application Suite
nodejs24
How to mitigate CVE-2026-9678
Netezza Appliance - update to 1.0.2.0
IBM Maximo Application Suite - addressed in versions 9.0.29, 9.1.21, 9.2.2
Netezza Appliance - Cyclops - update to 11.3.1.4
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in undici
- Multiple vulnerabilities in IBM Netezza Appliance
- Fedora 44 update for nodejs24
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 8 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Netezza Appliance - Cyclops