undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
Published Sep 4, 2026
7.4
HIGHCVSS 3.1
EPSS 0.16%
Description
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.
Affected products
-
Affected
- ≥ 8.10.0, < 8.10.2
Unaffected
- 8.10.2
No data.
Red Hat Hardened Images
grafana12-4-main-12.4.9-0.6.hum1
Fixed · RHSA-2026:63782
Red Hat Hardened Images
nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1
Fixed · RHSA-2026:54438
Red Hat Hardened Images
nodejs26-main-26.7.0-1.5.2.hum1
Fixed · RHSA-2026:54389
Exploit Intelligence
exploit-intelligence/vulnerability-analysis-rhel9
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-pf5-rhel9
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel9
Affected
Red Hat AMQ Broker 7
amq-broker-bin.zip
Not affected
Red Hat AMQ Broker 7
amq-broker-maven-repository.zip
Affected
Red Hat Ansible Automation Platform 2
automation-platform-ui
Not affected
Red Hat Build of Podman Desktop
rh-podman-desktop.git
Affected
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend
Not affected
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend
Not affected
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki
Not affected
Red Hat Developer Hub
rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator
Not affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Red Hat Enterprise Linux 10
grafana
Not affected
Red Hat Enterprise Linux 10
nodejs22
Will not fix
Red Hat Enterprise Linux 10
nodejs24
Affected
Red Hat Enterprise Linux 10
nodejs26
Affected
Red Hat Enterprise Linux 10
rhel10/nodejs-24
Affected
Red Hat Enterprise Linux 10
rhel10/nodejs-24-minimal
Affected
Red Hat Enterprise Linux 10
ubi10/nodejs-24
Not affected
Red Hat Enterprise Linux 10
ubi10/nodejs-24-minimal
Not affected
Red Hat Enterprise Linux 8
nodejs:22/nodejs
Will not fix
Red Hat Enterprise Linux 8
nodejs:24/nodejs
Affected
Red Hat Enterprise Linux 8
ubi8/nodejs-24
Affected
Red Hat Enterprise Linux 8
ubi8/nodejs-24-minimal
Affected
Red Hat Enterprise Linux 9
nodejs:22/nodejs
Will not fix
Red Hat Enterprise Linux 9
nodejs:24/nodejs
Affected
Red Hat Enterprise Linux 9
nodejs:26/nodejs
Affected
Red Hat Enterprise Linux 9
rhel9/nodejs-24
Affected
Red Hat Enterprise Linux 9
rhel9/nodejs-24-minimal
Affected
Red Hat Enterprise Linux 9
ubi9/nodejs-24
Not affected
Red Hat Enterprise Linux 9
ubi9/nodejs-24-minimal
Not affected
Red Hat Hardened Images
jaeger
Not affected
Red Hat Hardened Images
nodejs25
Will not fix
Red Hat Hardened Images
prometheus3.13
Not affected
Red Hat Hardened Images
rust
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-core-bff-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-operator-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-dashboard-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-agent-ops-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-automl-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-autorag-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-eval-hub-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-gen-ai-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-maas-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-mlflow-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mod-arch-model-registry-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-monitoring-plugin-rhel9
Affected
Red Hat OpenShift Container Platform 4
wasmedge
Affected
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Affected
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel9
Affected
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Not affected
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel9
Affected
Red Hat Openshift Data Foundation 4
odf4/ocs-client-console-rhel9
Affected
Red Hat Openshift Data Foundation 4
odf4/odf-console-rhel9
Affected
Red Hat Openshift Data Foundation 4
odf4/odf-multicluster-console-rhel9
Affected
Red Hat Trusted Artifact Signer
rhtas/rhtas-console-ui-rhel9
Affected
Secrets Management Console for Red Hat OpenShift
external-secrets-management/console-plugin-rhel9
Will not fix
Self-service automation portal 2
ansible-automation-platform/automation-portal
Affected
Self-service automation portal 2
ansible-automation-platform/bootc-automation-portal-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | grafana12-4-main-12.4.9-0.6.hum1 | Fixed | RHSA-2026:63782 |
| Red Hat Hardened Images | nodejs24-main-11.16.0-1.24.18.1.0.2.2.hum1 | Fixed | RHSA-2026:54438 |
| Red Hat Hardened Images | nodejs26-main-26.7.0-1.5.2.hum1 | Fixed | RHSA-2026:54389 |
| Exploit Intelligence | exploit-intelligence/vulnerability-analysis-rhel9 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-pf5-rhel9 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel9 | Affected | n/a |
| Red Hat AMQ Broker 7 | amq-broker-bin.zip | Not affected | n/a |
| Red Hat AMQ Broker 7 | amq-broker-maven-repository.zip | Affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-platform-ui | Not affected | n/a |
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Affected | n/a |
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend | Not affected | n/a |
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend | Not affected | n/a |
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki | Not affected | n/a |
| Red Hat Developer Hub | rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator | Not affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 10 | nodejs22 | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | nodejs24 | Affected | n/a |
| Red Hat Enterprise Linux 10 | nodejs26 | Affected | n/a |
| Red Hat Enterprise Linux 10 | rhel10/nodejs-24 | Affected | n/a |
| Red Hat Enterprise Linux 10 | rhel10/nodejs-24-minimal | Affected | n/a |
| Red Hat Enterprise Linux 10 | ubi10/nodejs-24 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | ubi10/nodejs-24-minimal | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:22/nodejs | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | nodejs:24/nodejs | Affected | n/a |
| Red Hat Enterprise Linux 8 | ubi8/nodejs-24 | Affected | n/a |
| Red Hat Enterprise Linux 8 | ubi8/nodejs-24-minimal | Affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:22/nodejs | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | nodejs:24/nodejs | Affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:26/nodejs | Affected | n/a |
| Red Hat Enterprise Linux 9 | rhel9/nodejs-24 | Affected | n/a |
| Red Hat Enterprise Linux 9 | rhel9/nodejs-24-minimal | Affected | n/a |
| Red Hat Enterprise Linux 9 | ubi9/nodejs-24 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ubi9/nodejs-24-minimal | Not affected | n/a |
| Red Hat Hardened Images | jaeger | Not affected | n/a |
| Red Hat Hardened Images | nodejs25 | Will not fix | n/a |
| Red Hat Hardened Images | prometheus3.13 | Not affected | n/a |
| Red Hat Hardened Images | rust | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-core-bff-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-operator-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-dashboard-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-agent-ops-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-automl-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-autorag-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-eval-hub-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-gen-ai-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-maas-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-mlflow-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mod-arch-model-registry-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-monitoring-plugin-rhel9 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | wasmedge | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel9 | Affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel9 | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/ocs-client-console-rhel9 | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-console-rhel9 | Affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-console-rhel9 | Affected | n/a |
| Red Hat Trusted Artifact Signer | rhtas/rhtas-console-ui-rhel9 | Affected | n/a |
| Secrets Management Console for Red Hat OpenShift | external-secrets-management/console-plugin-rhel9 | Will not fix | n/a |
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Affected | n/a |
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Affected | n/a |
undici
npm
Introduced 8.10.0 Fixed 8.10.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | undici | 8.10.0 | 8.10.2 |
Remediation
Red Hat statement
This flaw is present in the undici HTTP client library used by Node.js. When an application composes undici's Cache or Deduplicate interceptor directly onto a Client or Pool object (rather than onto an Agent), the library's internal cache and in-flight-request deduplication keys omit the destination origin. As a result, a cached or in-flight response captured for one upstream origin can be returned for a request intended for a different, trusted origin whenever the method, path, and relevant headers match. In the most severe demonstrated scenario, this allowed an attacker-controlled JWT to be accepted by the application as though it had been validated against a legitimate, trusted issuer, without that issuer ever being contacted — resulting in a full authentication bypass. Exploitation requires that the affected application attach the Cache or Deduplicate interceptor directly to a Client/Pool — the default Agent-based dispatch path is not affected, since Agent already carries the origin in its dispatch options — and that an attacker can influence or collide with the cache/deduplication key for at least one origin the application communicates with.).
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible to undici 8.10.2 or later.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-85152 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2528717 Issue Tracking
- https://cna.openjsf.org/security-advisories.html Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71474 Advisory
- https://github.com/advisories/GHSA-vp8m-p9jh-q5pm Advisory
- https://github.com/nodejs/undici/commit/caf6194d3dae989b731ed87ab85f182befe5eb80
- https://github.com/nodejs/undici/releases/tag/v8.10.2
- https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85152
- https://www.cve.org/CVERecord?id=CVE-2026-85152
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub