LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-85152

Published
CVSS7.4
Severityhigh
WeaknessCWE-346
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. Thi

References

← Back to the CVE Tracker

Our coverage of CVE-2026-85152

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-85152.