---
id: CVE-2026-9679
title: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
summary: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
severity: medium
cvss: 5.9
cwe:
  - CWE-93
vendor: undici
product: undici
affected:
  - undici < 6.27.0
  - 'undici >= 7.0.0, < 7.28.0'
  - 'undici >= 8.0.0, < 8.5.0'
patched:
  - undici 6.27.0
  - undici 7.28.0
  - undici 8.5.0
published: '2026-06-19'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-p88m-4jfj-68fv'
references:
  - url: 'https://github.com/nodejs/undici/security/advisories/GHSA-p88m-4jfj-68fv'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9679'
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: 'https://github.com/advisories/GHSA-p88m-4jfj-68fv'
tags:
  - ghsa
  - npm
epss: 0.00257
epssPercentile: 0.1769
ingestedAt: '2026-06-22T15:59:08.196Z'
ecosystem: npm
---

## Overview

## Impact

undici's cookie parser in `parseSetCookie` percent-decodes cookie values via `qsUnescape`, turning encoded sequences like `%0D%0A`, `%00`, `%3B`, and `%3D` into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either.

Applications that parse a `Set-Cookie` header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary `Set-Cookie`, `Location`, or `Cache-Control` headers into the application's downstream response, enabling session fixation, open redirect, or cache poisoning.

Affected applications are those that use undici's cookie parsing (`parseSetCookie`, `parseCookie`, `getSetCookies`) and forward the parsed cookie value into a response header.

This was introduced in undici 7.0.0 via [#3789](https://github.com/nodejs/undici/pull/3789).

## Patches

Upgrade to undici v6.27.0, v7.28.0 or v8.5.0.

## Workarounds

If upgrade is not immediately possible, do not forward values returned by `parseSetCookie`/`parseCookie`/`getSetCookies` directly into response headers; sanitize the value first to strip or reject CR, LF, NUL, `;`, and `=` bytes.

## Affected packages

- `undici < 6.27.0`
- `undici >= 7.0.0, < 7.28.0`
- `undici >= 8.0.0, < 8.5.0`

## Remediation

Upgrade to a patched release:

- `undici 6.27.0`
- `undici 7.28.0`
- `undici 8.5.0`
