CVE-2026-85152: undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
undicito a version that resolves this vulnerability.Fixed in 8.10.2
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use undici 8.10.0 through 8.10.2 with the cache or deduplicate interceptor composed directly onto a Client or Pool. Applications using an Agent are not affected because the Agent includes the origin in its dispatch options.
What conditions are required for exploitation?
An attacker needs requests to different upstream origins to have matching method, path, and relevant headers, so that a cacheable or in-flight response for one origin can be reused for another. This can expose cross-origin data or allow persistent cache poisoning; the reported demonstration achieved authentication bypass with an attacker-controlled JWT issuer.
What should be done if the affected interceptor setup is in use?
Upgrade undici to 8.10.2. If the interceptor is composed directly on a Client or Pool, using an Agent instead avoids the affected origin-less cache and deduplication key behavior.