THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jr45-8vmc-qm54 (medium) — undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

[GHSA] GHSA-jr45-8vmc-qm54 (medium) — undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

medgithub_advisoriesPublished 2026-08-03

GHSA-jr45-8vmc-qm54 Severity: medium CVE: CVE-2026-14643

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

## Impact

Undici's cache interceptor mishandles optional whitespace (OWS) placed around the `=` of a qualified `no-cache` or `private` Cache-Control directive, such as `no-cache ="authorization"` (OWS before `=`) or `no-cache= "

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jr45-8vmc-qm54