Executive brief
Undici, a popular HTTP client for Node.js, contains a flaw in how it handles website cookies. When processing cookies, the library incorrectly converts certain encoded characters into raw commands that web servers use to structure their responses. If an application uses this library to pass cookies from one server to another (such as in a proxy or middleware), an attacker could inject malicious instructions. This can lead to serious security issues like hijacking user sessions, redirecting users to malicious websites, or corrupting web caches.
Technical details
The vulnerability exists in undici's cookie parsing functions (parseSetCookie, parseCookie, getSetCookies) which use qsUnescape to percent-decode cookie values. This behavior deviates from RFC 6265 and browser standards, which do not specify decoding. By sending encoded sequences like %0D%0A (CRLF), %00 (NUL), %3B (;), or %3D (=), an attacker-controlled upstream server can cause the undici-based application to inject arbitrary headers into downstream responses. This CRLF injection (CWE-93) can be leveraged for session fixation, open redirects, or cache poisoning. The issue was introduced in version 7.0.0 and is patched in versions 6.27.0, 7.28.0, and 8.5.0.
Affected products
- Node.js undici < 6.27.0, 7.0.0 < 7.28.0, 8.0.0 < 8.5.0
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-17: patched