SCA: security update for undici (GHSA-vp8m-p9jh-q5pm)

high Tenable Cloud Security Plugin ID 448483

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or
deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls
back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for
a request to a different, trusted origin whenever the method, path, and relevant headers match, which
permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a
full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging
to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0
and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the
origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2. (CVE-2026-85152)

Solution

Update the undici library and its related packages to version 8.10.2 or later.

See Also

https://github.com/advisories/GHSA-vp8m-p9jh-q5pm

Plugin Details

Severity: High

ID: 448483

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/29/2026

Updated: 9/29/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.48

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.1

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-85152

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/29/2026

Vulnerability Publication Date: 9/4/2026

Reference Information

CVE: CVE-2026-85152

cwe: CWE-346