THREAT OPS › Threat News › [NVD] CVE-2026-84933 (MEDIUM 6.5) — undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example o
[NVD] CVE-2026-84933 (MEDIUM 6.5) — undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example o
CVE-2026-84933 CVSS: 6.5 MEDIUM Published: 2026-09-04T17:17:01.973
undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is st
Indicators of compromise
- CVE-2026-84933cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84933