
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16729 is a cookie attribute injection vulnerability in the Node.js HTTP client library undici, where the setCookie function fails to fully sanitize cookie attributes. Specifically, validateCookieDomain does not reject semicolons, and entries in the unparsed array are not sanitized, allowing attacker-influenced input to inject additional cookie attributes. Affected versions include undici before 6.28.0, 7.0.0 up to before 7.29.0, and 8.0.0 up to before 8.9.0. The vulnerability was published on July 29, 2026, and has a CVSS v3.1 base score of 4.8 (Moderate) per the GitHub Security Advisory, though NVD assigns 6.5 (Medium) (GitHub Advisory, undici Advisory).
The root cause is CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). There are two distinct injection paths: first, validateCookieDomain does not check for semicolons (unlike validateCookiePath, which already blocks 0x3B), so a domain value such as example.com; SameSite=None is passed verbatim, appending the SameSite attribute without the caller's intent. Second, the unparsed array loop only verifies that each entry contains = but does not sanitize values, meaning an entry like X-Custom=val; HttpOnly injects HttpOnly without cookie.httpOnly being set to true. Exploitation requires that the application passes user-controlled input to the domain field or unparsed array of setCookie — a condition most likely in multi-tenant or reverse-proxy architectures (GitHub Advisory, undici Advisory).
Successful exploitation allows an unauthenticated attacker to bypass SameSite CSRF protections by injecting SameSite=None or similar attributes into session cookies, or to force, strip, or override Secure, HttpOnly, and SameSite attributes without the application explicitly setting them. This can expose session cookies to cross-site request forgery attacks or weaken cookie security posture in ways the application developer did not intend. The impact is primarily on confidentiality (low) and integrity (low), with no availability impact; availability of the service is unaffected (GitHub Advisory, undici Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.167% (6th percentile), indicating a low near-term probability of exploitation. NVD's SSVC assessment classifies exploitation as "none" and automation as "no," reflecting the requirement for user-controlled input to reach the vulnerable code paths.
setCookie function's domain field or unparsed array.attacker.com; SameSite=None, as the tenant domain or any user-controlled field that flows into setCookie.unparsed array, supply an entry like X-Custom=val; HttpOnly to inject the HttpOnly attribute without the application explicitly enabling it, or X-Custom=val; Secure=false to strip the Secure flag.Set-Cookie: session=abc; Domain=attacker.com; SameSite=None.SameSite=None injected, perform cross-site request forgery (CSRF) attacks against the victim's session, or leverage stripped Secure/HttpOnly attributes to intercept or access the cookie via JavaScript or plaintext channels (GitHub Advisory, undici Advisory).Set-Cookie response headers containing unexpected attributes (e.g., SameSite=None, HttpOnly, or Secure appearing without application configuration); cookie domain values containing semicolons or unexpected attribute strings.Set-Cookie headers that include attributes not configured by the application.Secure or HttpOnly flags, or unexpectedly carrying SameSite=None, in environments where these were not explicitly set by the developer.Upgrade undici to a patched version: 6.28.0 (for 6.x users), 7.29.0 (for 7.x users), or 8.9.0 (for 8.x users). As a workaround prior to patching, sanitize all domain values against the RFC 1034 letter-digit-hyphen character set before passing them to setCookie, and avoid passing any user-controlled data to the unparsed field entirely. Applications that do not pass user-controlled input to setCookie's domain or unparsed fields are not affected (GitHub Advisory, undici Advisory).
The advisory was published by maintainer mcollina and reviewed by UlisesGascon and mcollina on the nodejs/undici repository. The vulnerability was reported by Zelys-DFKH. No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and scanner updates from Tenable and OSV (undici Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."