What is CVE-2026-14643?
This vulnerability exists in undici's cache interceptor, which mishandles optional whitespace around the equals sign of a qualified Cache-Control directive. As a result, directives like no-cache or private may be dropped or stored incorrectly. Users should upgrade to version 7.29.0 or 8.9.0 or later to address this issue.
Azərbaycanca: Bu boşluq undici kitabxanasının "cache interceptor" funksiyasında "Cache-Control" başlığındakı bərabər işarəsi ətrafında olan boşluqların düzgün işlənməməsi ilə bağlıdır. Nəticədə, "no-cache" və ya "private" kimi direktivlər ya itirilir, ya da səhvən saxlanılır. Zərərçəkən istifadəçilər 7.29.0 və ya 8.9.0 versiyalarına yeniləmə aparmalıdırlar.
FAQ2
In which function of the undici library was CVE-2026-14643 discovered?
This vulnerability was discovered in the cache interceptor function of the undici library.
What is the recommended upgrade to remediate CVE-2026-14643?
Affected users should upgrade to version 7.29.0 or 8.9.0 of the undici library.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.