Junglewise Threat Intelligence

CVE-2026-16729: Node.js undici cookie attribute injection in setCookie

CVE-2026-16729 · Severity: medium · CVSS 4.8 · Published 2026-07-29

Vendors: Nodejs.

Executive brief

Undici, a popular HTTP client for Node.js, contains a vulnerability in how it handles web cookies. If an application allows users to influence cookie settings (common in multi-tenant or proxy services), an attacker could inject malicious cookie attributes. This could allow them to bypass security protections like CSRF defenses or manipulate how session data is stored and secured.

Technical details

The `setCookie` function in Undici contains two injection paths due to improper neutralization of special elements (CWE-74). First, `validateCookieDomain` fails to reject semicolons, allowing an attacker to append additional attributes (e.g., `SameSite=None`) to the `domain` value. Second, the `unparsed` array loop only checks for the presence of an equals sign without sanitizing values, allowing arbitrary attribute injection. Attackers can exploit this to bypass SameSite CSRF protections or force/strip `Secure` and `HttpOnly` flags. The vulnerability is patched in versions 6.28.0, 7.29.0, and 8.9.0.

Affected products

  • nodejs undici < 6.28.0, >= 7.0.0 < 7.29.0, >= 8.0.0 < 8.9.0

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched
  • 2026-08-03: advisory

References