CVE-2026-16729: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-16729 is a cookie attribute injection vulnerability in the Node.js HTTP client library undici, where the setCookie function fails to fully sanitize cookie attributes. Specifically, validateCookieDomain does not reject semicolons, and entries in the unparsed array are not sanitized, allowing attacker-influenced input to inject additional cookie attributes. Affected versions include undici before 6.28.0, 7.0.0 up to before 7.29.0, and 8.0.0 up to before 8.9.0. The vulnerability was published on July 29, 2026, and has a CVSS v3.1 base score of 4.8 (Moderate) per the GitHub Security Advisory, though NVD assigns 6.5 (Medium) (GitHub Advisory, undici Advisory).

Technical details

The root cause is CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). There are two distinct injection paths: first, validateCookieDomain does not check for semicolons (unlike validateCookiePath, which already blocks 0x3B), so a domain value such as example.com; SameSite=None is passed verbatim, appending the SameSite attribute without the caller's intent. Second, the unparsed array loop only verifies that each entry contains = but does not sanitize values, meaning an entry like X-Custom=val; HttpOnly injects HttpOnly without cookie.httpOnly being set to true. Exploitation requires that the application passes user-controlled input to the domain field or unparsed array of setCookie — a condition most likely in multi-tenant or reverse-proxy architectures (GitHub Advisory, undici Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to bypass SameSite CSRF protections by injecting SameSite=None or similar attributes into session cookies, or to force, strip, or override Secure, HttpOnly, and SameSite attributes without the application explicitly setting them. This can expose session cookies to cross-site request forgery attacks or weaken cookie security posture in ways the application developer did not intend. The impact is primarily on confidentiality (low) and integrity (low), with no availability impact; availability of the service is unaffected (GitHub Advisory, undici Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.167% (6th percentile), indicating a low near-term probability of exploitation. NVD's SSVC assessment classifies exploitation as "none" and automation as "no," reflecting the requirement for user-controlled input to reach the vulnerable code paths.

Exploitation steps

  1. Identify a vulnerable target: Find a multi-tenant or reverse-proxy Node.js application using undici versions before 6.28.0, 7.0.0–7.28.x, or 8.0.0–8.8.x that passes user-supplied input (e.g., a tenant-supplied domain) to the setCookie function's domain field or unparsed array.
  2. Craft a malicious domain value: Supply a domain string containing a semicolon followed by a desired cookie attribute, such as attacker.com; SameSite=None, as the tenant domain or any user-controlled field that flows into setCookie.
  3. Inject via the unparsed array: Alternatively, if the application passes user input to the unparsed array, supply an entry like X-Custom=val; HttpOnly to inject the HttpOnly attribute without the application explicitly enabling it, or X-Custom=val; Secure=false to strip the Secure flag.
  4. Trigger cookie issuance: Cause the application to issue a session cookie using the manipulated input, resulting in a cookie header such as Set-Cookie: session=abc; Domain=attacker.com; SameSite=None.
  5. Exploit the weakened cookie: With SameSite=None injected, perform cross-site request forgery (CSRF) attacks against the victim's session, or leverage stripped Secure/HttpOnly attributes to intercept or access the cookie via JavaScript or plaintext channels (GitHub Advisory, undici Advisory).

Indicators of compromise

  • Network: Outbound Set-Cookie response headers containing unexpected attributes (e.g., SameSite=None, HttpOnly, or Secure appearing without application configuration); cookie domain values containing semicolons or unexpected attribute strings.
  • Logs: Application logs showing tenant-supplied domain values with semicolons or special characters being accepted without rejection; HTTP response logs with Set-Cookie headers that include attributes not configured by the application.
  • Application Behavior: Session cookies missing expected Secure or HttpOnly flags, or unexpectedly carrying SameSite=None, in environments where these were not explicitly set by the developer.

Mitigation and workarounds

Upgrade undici to a patched version: 6.28.0 (for 6.x users), 7.29.0 (for 7.x users), or 8.9.0 (for 8.x users). As a workaround prior to patching, sanitize all domain values against the RFC 1034 letter-digit-hyphen character set before passing them to setCookie, and avoid passing any user-controlled data to the unparsed field entirely. Applications that do not pass user-controlled input to setCookie's domain or unparsed fields are not affected (GitHub Advisory, undici Advisory).

Community reactions

The advisory was published by maintainer mcollina and reviewed by UlisesGascon and mcollina on the nodejs/undici repository. The vulnerability was reported by Zelys-DFKH. No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and scanner updates from Tenable and OSV (undici Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

node-undici

Affected

sid

node-undici: 8.9.0+dfsg+~cs3.2.0-1

Fixed

trixie

node-undici

Affected

Ubuntu

Unknown

devel

node-undici

Unknown

noble

node-undici

Unknown

noble (esm-apps)

node-undici

Unknown

resolute

node-undici

Unknown

resolute (esm-apps)

node-undici

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106557HIGH7.7
  • JavaScript logoJavaScript
  • @backstage/plugin-techdocs-node
NoYesOct 07, 2026
CVE-2026-106108MEDIUM5.6
  • JavaScript logoJavaScript
  • @quasar/app-vite
NoYesOct 07, 2026
CVE-2026-106563MEDIUM5.3
  • JavaScript logoJavaScript
  • @backstage/plugin-kubernetes-backend
NoYesOct 07, 2026
CVE-2026-106561MEDIUM5
  • JavaScript logoJavaScript
  • @backstage/plugin-kubernetes-backend
NoYesOct 07, 2026
CVE-2026-106562MEDIUM4.3
  • JavaScript logoJavaScript
  • @backstage/plugin-search-backend
NoYesOct 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management