What is CVE-2026-13697?
This vulnerability in undici's cache interceptor mishandles malformed Cache-Control private directives, potentially allowing responses with degenerate private values to be stored in the shared cache. Affected versions include undici 7.0.0 to before 7.29.0 and 8.0.0 to before 8.9.0, leading to unintended exposure of private data. Users should immediately upgrade and review cache configurations.
Azərbaycanca: Bu boşluq undici kitabxanasının keş interceptor-unun səhv formatlanmış Cache-Control 'private' direktivlərini düzgün işləməməsindən qaynaqlanır. Təsirə məruz qalan versiyalarda (7.0.0-7.29.0, 8.0.0-8.9.0) bu, paylaşılan keşdə məxfi məlumatların səhvən saxlanmasına səbəb ola bilər. İstifadəçilər dərhal kitabxananı yeniləməli və keş konfiqurasiyalarını nəzərdən keçirməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which specific component of the undici library does the CVE-2026-13697 vulnerability exist?
This vulnerability exists in undici's cache interceptor, which mishandles malformed Cache-Control private directives.
Which versions of undici are affected by the CVE-2026-13697 vulnerability?
Affected versions include undici 7.0.0 to before 7.29.0 and 8.0.0 to before 8.9.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.