UBUNTU-CVE-2026-85152

Source
https://ubuntu.com/security/CVE-2026-85152
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-85152.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-85152
Upstream
Published
2026-09-04T17:17:00Z
Modified
2026-09-16T14:02:38Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.

References

Affected packages

Ubuntu:24.04:LTS / node-undici

Package

Name
node-undici
Purl
pkg:deb/ubuntu/node-undici?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.22.1+dfsg1+~cs20.10.10.2-1ubuntu1
5.26.3+dfsg1+~cs23.10.12-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "node-llhttp",
            "binary_version": "9.1.3~5.26.3+dfsg1+~cs23.10.12-2"
        },
        {
            "binary_name": "node-undici",
            "binary_version": "5.26.3+dfsg1+~cs23.10.12-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-85152.json"

Ubuntu:26.04:LTS / node-undici

Package

Name
node-undici
Purl
pkg:deb/ubuntu/node-undici?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.3.0+dfsg1+~cs24.12.11-2
7.16.0+dfsg+~cs3.2.0-2
7.18.2+dfsg+~cs3.2.0-1
7.18.2+dfsg+~cs3.2.0-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "node-undici",
            "binary_version": "7.18.2+dfsg+~cs3.2.0-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-85152.json"