Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14643

CVE-2026-14643: undici Auth Bypass Vulnerability

CVE-2026-14643 is an authentication bypass flaw in undici's cache interceptor that allows unauthorized access to cached authenticated data. This article covers the technical details, affected versions, and mitigation steps.

Published:

CVE-2026-14643 Overview

CVE-2026-14643 affects undici, the HTTP/1.1 client used by Node.js. The cache interceptor mishandles optional whitespace around the equals sign in qualified no-cache or private Cache-Control directives. The parser either drops the directive or stores a field name with literal quote characters. As a result, the cache fails to honor the qualification and stores the response.

In shared-cache mode, an attacker can cause a response containing one user's authenticated data to be served from cache to a later, potentially unauthenticated caller when both requests resolve to the same cache key. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize.

Critical Impact

Authenticated user data can leak across sessions through the shared cache when upstream responses use whitespace-padded qualified Cache-Control directives.

Affected Products

  • undici versions 7.0.0 through 7.28.x (fixed in 7.29.0)
  • undici versions 8.0.0 through 8.8.x (fixed in 8.9.0)
  • Node.js applications using the undici cache interceptor in shared mode

Discovery Timeline

  • 2026-07-29 - CVE CVE-2026-14643 published to NVD
  • 2026-07-29 - Last updated in NVD database

Technical Details for CVE-2026-14643

Vulnerability Analysis

The flaw is an interpretation conflict [CWE-436] between the HTTP cache specification and the undici parser. HTTP allows qualified Cache-Control directives such as no-cache="Set-Cookie" or private="Authorization", which restrict caching behavior to specific header fields. RFC 7234 permits optional whitespace around the equals sign.

When an upstream response contains a directive like no-cache = "Set-Cookie" with whitespace surrounding the =, undici's parser fails. It either drops the directive entirely or retains the field name including literal quote characters. Neither outcome triggers the intended cache exclusion.

The cache interceptor then treats the response as fully cacheable. In shared-cache mode, undici serves this stored response to later requests that resolve to the same cache key, including requests from unauthenticated clients.

Root Cause

The parser does not normalize optional whitespace around the equals sign in qualified Cache-Control directives before evaluating them. The earlier fix for CVE-2026-9678 addressed related parsing gaps but omitted this whitespace variant.

Attack Vector

Exploitation requires a specific runtime configuration. The target application must enable the undici cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses that use qualified Cache-Control directives with whitespace-padded equals signs. An attacker sends a request following a legitimate authenticated request that shares the same cache key. The stored response, which should have excluded sensitive fields, is returned intact.

The vulnerability requires no authentication or user interaction from the attacker, but relies on upstream server behavior producing the malformed directive spacing. Refer to the GitHub Security Advisory GHSA-jr45-8vmc-qm54 for full technical detail.

Detection Methods for CVE-2026-14643

Indicators of Compromise

  • Upstream HTTP responses containing Cache-Control directives with whitespace around the equals sign, such as no-cache = "Set-Cookie" or private = "Authorization"
  • Cached responses served to unauthenticated clients that contain authenticated user data such as tokens, session identifiers, or personal information
  • Application logs showing repeated cache hits on endpoints that forward Authorization headers

Detection Strategies

  • Inventory Node.js applications using undici 7.0.07.28.x or 8.0.08.8.x with the cache interceptor enabled in shared mode
  • Inspect upstream responses for qualified Cache-Control directives and flag any that contain whitespace surrounding the equals sign
  • Correlate cache-hit telemetry with user session boundaries to identify potential cross-user response reuse

Monitoring Recommendations

  • Log Cache-Control header values received from upstream services and alert on non-normalized qualified directives
  • Monitor for anomalous response bodies served from cache that contain user-scoped data such as Set-Cookie or authentication artifacts
  • Track undici package versions across the build pipeline using software composition analysis tooling

How to Mitigate CVE-2026-14643

Immediate Actions Required

  • Upgrade undici to version 7.29.0 or 8.9.0 or later
  • Audit application code for use of undici cache interceptor in shared mode combined with forwarded Authorization headers
  • Purge any shared caches that may contain responses stored during the vulnerable window

Patch Information

The issue is fixed in undici 7.29.0 and 8.9.0. Both releases normalize optional whitespace around the equals sign in qualified Cache-Control directives before evaluation. See the GitHub Security Advisory GHSA-jr45-8vmc-qm54 and the OpenJS Foundation Security Advisories for full release notes.

Workarounds

  • Disable the undici cache interceptor until the patched version is deployed
  • Switch the interceptor from shared mode to private mode where feasible
  • Strip or rewrite qualified Cache-Control directives at an intermediate proxy to remove ambiguous whitespace before responses reach undici
bash
# Configuration example: upgrade undici to a patched release
npm install undici@^7.29.0
# or, for the 8.x line
npm install undici@^8.9.0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.