THREAT OPS › Threat News › [GHSA] GHSA-jr45-8vmc-qm54 (medium) — undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
[GHSA] GHSA-jr45-8vmc-qm54 (medium) — undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
GHSA-jr45-8vmc-qm54 Severity: medium CVE: CVE-2026-14643
undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives
## Impact
Undici's cache interceptor mishandles optional whitespace (OWS) placed around the `=` of a qualified `no-cache` or `private` Cache-Control directive, such as `no-cache ="authorization"` (OWS before `=`) or `no-cache= "
Indicators of compromise
- CVE-2026-14643cve
- CVE-2026-9678cve
Original source: https://github.com/advisories/GHSA-jr45-8vmc-qm54