CVE-2026-11525

Aliases:GHSA-g8m3-5g58-fq7mDEBIAN-CVE-2026-11525CGA-3p7j-fh88-jqf4CGA-46m2-c62j-f2rqCGA-4pr4-52ww-x528CGA-88hh-4xpw-vp53CGA-c996-7g4j-2jmmCGA-h4c4-rvmm-g2h3CGA-h7g8-hx83-jq2vCGA-j6gw-qxgj-3fp2CGA-mpx3-wh2r-75jfCGA-2gv9-ggr6-mffwCGA-3976-xhf6-gcm2CGA-3hw7-qjwf-mj9gCGA-3j82-393m-h92qCGA-3p99-wr5q-56jcCGA-3r7r-g9gj-4q3cCGA-4g3g-6m3r-4gffCGA-566q-h68w-jmhcCGA-5gq2-3hh3-xjgjCGA-5r68-rj7h-c226CGA-68pp-vmqg-v3j6CGA-6gcp-f3fr-r2wqCGA-6jwp-v934-jx59CGA-6vgq-4jfm-6f64CGA-7rmg-6pmr-3c6fCGA-867f-xgfp-qfwxCGA-87f6-9h9w-x7mvCGA-8j57-rxgm-2wgvCGA-8mhm-pr8p-chcvCGA-8pmq-qq52-rrqwCGA-9wm8-cjc9-8fghCGA-9x88-j6w8-xwfqCGA-c5j8-wfjv-wvh4CGA-c666-m96q-j6x3CGA-cfq9-mq2g-hjmfCGA-f584-5fhf-3w5pCGA-fgcv-hj9h-93c8CGA-frf9-fr39-84g9CGA-gj76-8h9h-7366CGA-gr6x-5g4v-g9jjCGA-jgc6-v93m-hxr6CGA-jq5v-pjhg-q5jfCGA-m9f3-g74w-42mmCGA-mg37-4592-q639CGA-p7wp-x7ch-vcphCGA-ph94-fhmv-6qwrCGA-phqc-v2g3-x6jjCGA-q5c7-cfgc-4vqjCGA-r39x-8x3g-47jmCGA-r42q-4g6q-r4j4CGA-r8wm-j7gw-cwxxCGA-vc7m-jf5g-m388CGA-vp79-4rc4-3q72CGA-vpfv-jp5j-89prCGA-vqwx-8564-v6w7CGA-vw86-8v57-6w9fCGA-w4mj-ggfp-c797CGA-w798-3mxj-6825CGA-wfpx-62h6-p58mCGA-whmj-4fhr-g65qCGA-wrh9-rp5g-8mwgCGA-xv9p-rfp6-mg2pCGA-xwwc-6qv7-f75fCGA-499c-q242-3xw2CGA-pvj4-7w3w-f7ghCGA-vqfm-7xj3-j6gxCGA-gw78-rgjm-994pCGA-jcg8-jhq3-fhrjCGA-mg85-g8cf-gh5jCGA-29xh-h4j5-6x64CGA-4h8m-448j-3jj2CGA-gw49-44wc-7hcjCGA-hqcv-7p57-j824CGA-2hv7-gv7h-jqx4
Analyzed
Published: 17 Jun 2026, 17:31
Last modified:17 Jun 2026, 17:54

Vulnerability Summary

Overall Risk (default)
low
15/100
CVSS Score
3.7 LOW
v3.1 (cve.org)
EPSS Score
0.24% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jun 2026, 17:31
Published
Vulnerability first disclosed
17 Jun 2026, 17:54
Last Modified
Vulnerability information updated

Description

Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie header, validate that the resulting sameSite attribute is one of 'Strict', 'Lax', or 'None' (exact, case-insensitive) before forwarding or relying on it.

CVSS Metrics

  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.24% Percentile: 15%

Techniques & Countermeasures

  • CWE-183Permissive List of Allowed Inputs

    The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Affected Systems

  • chainguardactions-runner

    < 2.335.1-r1

  • chainguardcode-server

    < 4.125.0-r2

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardgemini-cli

    < 0.49.0-r4

  • chainguardharaka

    < 3.3.1-r1

  • chainguardkibana-8.19

    < 8.19.16-r6

  • chainguardkibana-8.19-bitnami

    < 8.19.16-r6

  • chainguardkibana-8.19-iamguarded

    < 8.19.16-r6

  • chainguardkibana-9.1

    < 9.1.10-r21

  • chainguardkibana-9.1-iamguarded

    < 9.1.10-r21

  • chainguardkibana-9.2

    < 9.2.8-r9

  • chainguardkibana-9.2-iamguarded

    < 9.2.8-r9

  • chainguardkibana-9.3

    < 9.3.5-r4

  • chainguardkibana-9.3-iamguarded

    < 9.3.5-r4

  • chainguardkibana-9.4

    < 9.4.2-r5

  • chainguardkibana-9.4-iamguarded

    < 9.4.2-r5

  • chainguardnode-gyp

    < 13.0.0-r1

  • chainguardnpm

    < 11.17.0-r1

  • chainguardpelias-api

    < 7.8.0-r4

  • chainguardprism

    < 5.15.11-r3

  • chainguardpy3.10-captum

    < 0.9.0-r1

  • chainguardpy3.11-captum

    < 0.9.0-r1

  • chainguardpy3.12-captum

    < 0.9.0-r1

  • chainguardpy3.13-captum

    < 0.9.0-r1

  • chainguardrenovate

    < 43.247.0-r0 | < 43.249.5-r2

  • chainguardsaf

    < 1.6.0-r2

  • chainguardvitess-24

    < 24.0.2-r1

  • chainguardvitess-24-compat

    < 24.0.3-r7

  • wolficode-server

    < 4.125.0-r2

  • wolfinode-gyp

    < 13.0.0-r1

  • wolfinpm

    < 11.17.0-r1

  • wolfiprism

    < 5.15.11-r3

  • wolfirenovate

    < 43.247.0-r0 | < 43.249.5-r2

  • wolfisaf

    < 1.6.0-r2

  • wolfivitess-24

    < 24.0.2-r1

  • wolfivitess-24-compat

    < 24.0.3-r7

  • debiannode-undici

    all | all | < 8.5.0+dfsg+~cs3.2.0-1

  • nodejsundici

    < 6.27.0 | ≥ 7.0.0, < 7.28.0 | ≥ 8.0.0, < 8.5.0

  • Npmundici

    < 6.27.0 | ≥ 7.0.0, < 7.28.0 | ≥ 8.0.0, < 8.5.0

  • undiciundici

    < 6.26.0 | ≥ 7.0.0, < 7.28.0 | ≥ 8.0.0, < 8.5.0

References (6)