What is CVE-2026-16729?
CVE-2026-16729 is an improper sanitization vulnerability in the `setCookie` function of the undici HTTP client library for Node.js. In affected versions prior to 6.28.0, 7.29.0, and 8.9.0, unparsed cookie attributes are not fully sanitized, allowing attackers to inject arbitrary cookie attributes via crafted input. Upgrading undici to the patched versions is strongly recommended.
Azərbaycanca: CVE-2026-16729 Node.js HTTP klienti olan undici kitabxanasında `setCookie` funksiyasında kukla atributlarının düzgün təmizlənməməsi zəifliyidir. Bu, təsirlənmiş versiyalarda (6.28.0, 7.29.0, 8.9.0-dan əvvəl) təcavüzkarın xüsusi hazırlanmış giriş vasitəsilə kuklalara əlavə parametrlər inject edə bilməsinə səbəb olur. undici kitabxanasını ən son yamaqlanmış versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which library is affected by CVE-2026-16729?
CVE-2026-16729 affects the undici HTTP client library for Node.js.
How can I protect against this vulnerability?
To protect against this vulnerability, it is recommended to upgrade undici to the patched versions: 6.28.0, 7.29.0, or 8.9.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.