[NPM:GHSA-WQQ4-5WPV-MX2G] Undici's cookie header not cleared on cross-origin redirect in fetch

Severity Low
Affected Packages 1
Fixed Packages 1
CVEs 1


Undici clears Authorization headers on cross-origin redirects, but does not clear Cookie headers. By design, cookie headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since Undici handles headers more liberally than the specification, there was a disconnect from the assumptions the spec made, and Undici's implementation of fetch.

As such this may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site.


This was patched in e041de359221ebeae04c469e8aff4145764e6d76, which is included in version 5.26.2.

Package Affected Version
pkg:npm/undici < 5.26.2
Package Fixed Version
pkg:npm/undici = 5.26.2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:npm/undici undici < 5.26.2
Fixed pkg:npm/undici undici = 5.26.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date