GHSA-vp8m-p9jh-q5pm: High severity npm/undici vulnerability

Published Sep 29, 2026
·
Updated

Impact

When interceptors.cache() or interceptors.deduplicate() is used with a dispatcher that does not carry a single authoritative origin, or when a request supplies its own origin, undici builds the cache and deduplication keys without the actual destination origin. If a cache store or interceptor instance is shared across more than one origin, otherwise-identical requests to different origins are keyed together.

An attacker who controls the response from one origin can then have that response returned for a request to a different, trusted origin when the method, path, and relevant headers match. This allows cross-origin information disclosure and persistent cache poisoning, including chains such as JWKS cache poisoning where a token signed with an attacker-held key is accepted as belonging to a trusted issuer.

Applications that share interceptors.cache() or interceptors.deduplicate() state across origins are affected. An Agent is not affected, because its dispatch options include the request origin.

This was introduced in undici 8.10.0 and affects 8.10.0 and 8.10.1.

Patches

Upgrade to undici v8.10.2.

Workarounds

Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.

Affected Software

1 affected componentFixes available
npm/undici>=8.10.0<8.10.2
8.10.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  2. Upgrade

    Upgrade undici to a version that resolves this vulnerability.

    Fixed in 8.10.2
  3. Configuration

    Use a separate cache store and a separate interceptor instance for each origin, and do not share them across origins.

    undici interceptors.cache() and interceptors.deduplicate() cache store and interceptor sharing across origins = separate per origin

Event History

Sep 29, 2026
Advisory Published
via GitHub·06:15 PM
Data Sourced
via GitHub·06:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Applications are affected when they share interceptors.cache() or interceptors.deduplicate() state across multiple origins using a dispatcher without a single authoritative origin, or when requests supply their own origin. undici versions 8.10.0 and 8.10.1 are affected; an Agent is not affected because its dispatch options include the request origin.

2

What must an attacker be able to do to exploit this?

The attacker must control a response from one origin that shares cache or deduplication state with a trusted origin. They can cause that response to be reused for a request to the trusted origin when the method, path, and relevant headers match.

3

What can be done if upgrading is not immediately possible?

Use a separate cache store and a separate interceptor instance for each origin. This prevents otherwise-identical requests to different origins from being keyed together.

4

How can we determine whether our application is exposed?

Review uses of interceptors.cache() and interceptors.deduplicate() to determine whether their cache store or interceptor instance is shared by requests to more than one origin. Requests that provide their own origin or use a dispatcher without one authoritative origin require particular attention.

5

What is the remediation?

Upgrade undici to version 8.10.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203