(undici), Caching and Replay of Unsafe HTTP Method Responses, CVE-2026-85008 (Low) -DC-Sep2026-2620

Listen to this Post

The undici HTTP client library contains a critical logic error in its cache interceptor mechanism. The interceptor’s documentation states that only safe HTTP methods are cached. However, the internal skip-list is built by subtracting the configured methods from the safe-methods set, which means an unsafe method such as POST, PUT, PATCH, or DELETE never lands in the skip-list. This causes these unsafe methods to be looked up against the cache store. Furthermore, the storage gate (canCacheResponse) has no method check. Consequently, a heuristically-cacheable response (for example, a 404) with an explicit Cache-Control: max-age=… header to an unsafe method is stored and later replayed on a subsequent identical request. The application’s state-changing request never reaches the origin; instead, undici serves a fabricated response from the cache. This occurs with the default configuration (methods: [‘GET’]), which the public API does not allow widening to unsafe methods. Therefore, no application misuse is required. An untrusted origin can trigger it purely through its own response headers, leading to an integrity failure. The flaw aligns with CWE-20 (Improper Input Validation) and CWE-345 (Insufficient Verification of Data Authenticity). The vulnerability affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2. The cache interceptor no longer reads from or writes to the cache for unsafe HTTP methods, while still invalidating existing cache entries on successful unsafe requests. There are no workarounds.

DailyCVE Form:

Platform: undici
Version: 7.0.0–7.29.1, 8.0.0–8.10.2
Vulnerability: Cache replay
Severity: Low
date: Sep 4, 2026

Prediction: Patch date: Sep 29, 2026

What Undercode Say:

Check installed undici version
npm list undici
Inspect cache interceptor configuration
node -e "const {interceptors} = require('undici'); console.log(interceptors.cache.toString())"
// Demonstrating the flawed skip-list logic (conceptual)
const safeMethods = new Set(['GET', 'HEAD', 'OPTIONS', 'TRACE']);
const configuredMethods = new Set(['GET']);
const skipList = new Set([...safeMethods].filter(m => !configuredMethods.has(m)));
console.log(skipList); // Set(3) { 'HEAD', 'OPTIONS', 'TRACE' } — 'POST' is absent

How Exploit: (Educational Purposes!)

An attacker-controlled origin responds to a safe request (e.g., GET) with a cacheable status and explicit Cache-Control: max-age=3600. The client then issues a state-changing request (e.g., POST) to the same path. undici looks up the unsafe method against the cache store, finds the previously stored response, and serves it without contacting the origin. The application believes the state change succeeded, but the origin never received the request.

Simulate origin returning cacheable 404 for a POST request
curl -X POST -H "Cache-Control: max-age=3600" https://attacker.example/state-change -i

Protection: Upgrade to undici 7.29.1 or 8.10.2. The cache interceptor no longer reads from or writes to the cache for unsafe HTTP methods. Ensure all dependencies are updated and monitor for any cached state-changing responses.
Impact: The application’s state-changing request never reaches the origin, and undici serves a fabricated response from the cache instead. This leads to integrity failures where application logic proceeds based on outdated or manipulated data without any interaction with the backend service.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top