THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4cwx-7wf7-3272 (high) — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

[GHSA] GHSA-4cwx-7wf7-3272 (high) — undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

highgithub_advisoriesPublished 2026-08-03

GHSA-4cwx-7wf7-3272 Severity: high CVE: CVE-2026-13697

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

### Summary

Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:

1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `privat

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4cwx-7wf7-3272