THREAT OPS › Threat News › [GHSA] GHSA-4cwx-7wf7-3272 (high) — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
[GHSA] GHSA-4cwx-7wf7-3272 (high) — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-4cwx-7wf7-3272 Severity: high CVE: CVE-2026-13697
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
### Summary
Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:
1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `privat
Indicators of compromise
- CVE-2026-13697cve
- https://hackerone.com/reports/3817497url
Original source: https://github.com/advisories/GHSA-4cwx-7wf7-3272