THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-84933 (MEDIUM 6.5) — undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example o

[NVD] CVE-2026-84933 (MEDIUM 6.5) — undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example o

mednvdPublished 2026-09-04

CVE-2026-84933 CVSS: 6.5 MEDIUM Published: 2026-09-04T17:17:01.973

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is st

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-84933