Echo: undici: security update to 6.27.0

medium Tenable Self-Hosted Container Security Plugin ID 463259

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning
encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §5.4 does
not specify any decoding and browsers do not decode either. Applications that parse a Set-Cookie header
and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become
vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary Set-
Cookie, Location, or Cache-Control headers into the application's downstream response, enabling session
fixation, open redirect, or cache poisoning. Affected applications are those that use undici's cookie
parsing (parseSetCookie, parseCookie, getSetCookies) and forward the parsed cookie value into a response
header. This was introduced in undici 7.0.0 via PR #3789. Patches: Upgrade to undici v6.26.0, v7.28.0 or
v8.5.0. Workarounds: If upgrade is not immediately possible, do not forward values returned by
parseSetCookie/parseCookie/getSetCookies directly into response headers; sanitize the value first to strip
or reject CR, LF, NUL, ;, and = bytes. (CVE-2026-9679)

Solution

Update the undici library and its related packages to version 6.27.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-9679

Plugin Details

Severity: Medium

ID: 463259

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2026-9679

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/18/2026

Vulnerability Publication Date: 6/17/2026

Reference Information

CVE: CVE-2026-9679

IAVB: 2026-B-0170-S