ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
undici (npm) · published 2026-08-03

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

CVE-2026-13697 — CVSS 7.4/10. Fix: upgrade to 7.29.0.
Package
undici
Ecosystem
npm
Vector
NETWORK
Complexity
HIGH
Privileges
NONE
Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
HIGH

Summary

Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:

1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=""` or `private=","` can be incorrectly stored in the default shared cache, then served to a later caller with the same cache key.

2. **Parse-time crash:** Mixed unqualified-and-qualified `private` directives in the same header (such as `public, max-age=60, private, private="hdr"`) cause an uncaught `TypeError` in the cache-control parser, terminating the request.

Impact

Shared-cache disclosure

Applications using `interceptors.cache()` in shared mode may cache a user-specific response and serve it to a later caller with the same cache key. This can disclose private response bodies and headers, including `Set-Cookie`.

Required conditions:

- the cache interceptor is enabled in shared mode, including the default configuration;

- an upstream returns a malformed directive such as `Cache-Control: public, max-age=300, private=""`;

- another request later matches the same cache key, without a separating `Vary` header.

Parse-time crash

Weakness classes: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) · CWE-248 (Uncaught Exception) · CWE-525 (Use of Web Browser Cache Containing Sensitive Information)

Source: GHSA-4cwx-7wf7-3272 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.