Executive brief
Undici, a popular HTTP client for Node.js, contains a flaw in how it handles cached web responses. When configured to share a cache between different users, the library may fail to recognize security instructions that are supposed to keep sensitive data private if those instructions contain extra spaces. This could allow one user's private, authenticated information to be accidentally served to a different, potentially unauthenticated user.
Technical details
A vulnerability exists in Undici's cache interceptor due to improper parsing of optional whitespace (OWS) around the equals sign in 'no-cache' or 'private' Cache-Control directives (e.g., 'no-cache =\"authorization\"'). The parser fails to normalize this whitespace, causing it to either drop the directive or store the field name incorrectly. In shared-cache mode, this leads to an interpretation conflict where the cache fails to exclude sensitive headers like 'Authorization' from the stored response. Consequently, an attacker or subsequent user sharing the same cache key can retrieve a cached response containing another user's authenticated data. The issue is patched in versions 7.29.0 and 8.9.0.
Affected products
- Node.js undici >= 7.0.0, < 7.29.0; >= 8.0.0, < 8.9.0
Timeline
- 2026-07-29: patched: Fixes released in v7.29.0 and v8.9.0
- 2026-07-29: disclosed
- 2026-08-03: advisory