---
id: CVE-2026-16729
aliases:
  - GHSA-v3r7-h72x-cjcm
title: >-
  undici vulnerable to cookie attribute injection via unsanitized domain and
  unparsed setCookie fields
summary: >-
  undici vulnerable to cookie attribute injection via unsanitized domain and
  unparsed setCookie fields
severity: medium
cvss: 4.8
cwe:
  - CWE-74
vendor: undici
product: undici
ecosystem: npm
affected:
  - undici < 6.28.0
  - 'undici >= 7.0.0, < 7.29.0'
  - 'undici >= 8.0.0, < 8.9.0'
patched:
  - undici 6.28.0
  - undici 7.29.0
  - undici 8.9.0
published: '2026-08-03'
updated: '2026-08-03'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-v3r7-h72x-cjcm'
references:
  - url: 'https://github.com/nodejs/undici/security/advisories/GHSA-v3r7-h72x-cjcm'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16729'
  - url: >-
      https://github.com/nodejs/undici/commit/10d93fc332f2c8c161982dec3833201de29891b5
  - url: >-
      https://github.com/nodejs/undici/commit/3bf91ddb493e853957f3a58e155326a668ab8aef
  - url: >-
      https://github.com/nodejs/undici/commit/af7484043ee075a6f216da0ad77e1dac55199235
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: 'https://github.com/nodejs/undici/releases/tag/v6.28.0'
  - url: 'https://github.com/nodejs/undici/releases/tag/v7.29.0'
  - url: 'https://github.com/nodejs/undici/releases/tag/v8.9.0'
  - url: 'https://github.com/advisories/GHSA-v3r7-h72x-cjcm'
tags:
  - ghsa
  - npm
epss: 0.00191
epssPercentile: 0.07695
ingestedAt: '2026-08-03T20:29:32.731Z'
---

## Overview

## Impact

The `setCookie` function has two attribute injection paths. `validateCookieDomain` does not reject semicolons (`validateCookiePath` already does at 0x3B), so a `domain` value like `example.com; SameSite=None` lands verbatim as `Domain=example.com; SameSite=None`. The `unparsed` array's loop only checks each entry contains `=` and does not sanitize values, so an entry like `X-Custom=val; HttpOnly` lands unchanged, injecting `HttpOnly` without the caller setting `cookie.httpOnly = true`.

Applications that pass user-controlled input to these fields, typically multi-tenant or reverse-proxy servers that scope session cookies to a tenant-supplied domain, can have SameSite CSRF protections bypassed, `Secure` or `HttpOnly` forced or stripped, or the intended SameSite tier overridden.

## Patches

Patched in undici v6.28.0, v7.29.0, and v8.9.0.

## Workarounds

- Sanitize `domain` values against the RFC 1034 letter-digit-hyphen set before passing to `setCookie`.
- Do not pass user-controlled data to the `unparsed` field.

## Affected packages

- `undici < 6.28.0`
- `undici >= 7.0.0, < 7.29.0`
- `undici >= 8.0.0, < 8.9.0`

## Remediation

Upgrade to a patched release:

- `undici 6.28.0`
- `undici 7.29.0`
- `undici 8.9.0`
