SCA: security update for undici (GHSA-jr45-8vmc-qm54)

medium Tenable Cloud Security Plugin ID 445602

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-
cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to
before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters,
so the cache decision fails to recognize the qualification and the response is stored. In shared-cache
mode, this lets a response containing one user's authenticated data be served from cache to a later
caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects
applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and
receive cacheable responses with qualified directives padded with whitespace around the equals sign. This
is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed
in undici 7.29.0 and 8.9.0. (CVE-2026-14643)

Solution

Update the undici library and its related packages to version 7.29.0 or later.

See Also

https://github.com/advisories/GHSA-jr45-8vmc-qm54

Plugin Details

Severity: Medium

ID: 445602

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/4/2026

Updated: 8/4/2026

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.92

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-14643

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/3/2026

Vulnerability Publication Date: 7/29/2026

Reference Information

CVE: CVE-2026-14643