Origin Validation Error Affecting undici package, versions >=8.10.0 <8.10.2


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.21% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-UNDICI-19635224
  • published6 Sept 2026
  • disclosed4 Sept 2026
  • creditNikola Kojic

Introduced: 4 Sep 2026

NewCVE-2026-85152  (opens in a new tab)
CWE-346  (opens in a new tab)

How to fix?

Upgrade undici to version 8.10.2 or higher.

Overview

undici is an An HTTP/1.1 client, written from scratch for Node.js

Affected versions of this package are vulnerable to Origin Validation Error leading to cache poisoning in the interceptors.cache() and interceptors.deduplicate() interceptors, which build cache and deduplication keys without the actual destination origin when the dispatcher lacks a single authoritative origin or requests supply their own origin. An attacker who controls responses from one origin can have them returned for requests to a different, trusted origin whose method, path, and relevant headers match, enabling cross-origin information disclosure and persistent cache poisoning such as JWKS poisoning. This requires a cache store or interceptor instance shared across multiple origins, together with a dispatcher that has no single authoritative origin or requests that carry their own origin.

Workaround

This vulnerability can be avoided by using separate cache stores and interceptor instances per origin rather than sharing them across origins, so requests to different origins cannot share a cache key.

CVSS Base Scores

version 4.0
version 3.1