CVE-2026-13697

Aliases:UBUNTU-CVE-2026-13697DEBIAN-CVE-2026-13697GHSA-4cwx-7wf7-3272CGA-4r6j-3927-j8hfCGA-52vc-xgfj-vfvwCGA-5rcf-q5fp-99gvCGA-64p7-wr7q-hxw9CGA-669w-w4ph-42g6CGA-8w2f-whv2-x2rqCGA-f478-qvxg-p5pcCGA-ffv8-qvvj-559hCGA-jj65-c4cx-hw34CGA-mjw4-3chr-g3c7CGA-2w46-3522-735hCGA-377j-q67r-ppf6CGA-3w88-jjmw-9w4rCGA-584v-828q-fx82CGA-6273-9x66-28gxCGA-66q8-2gf7-pm74CGA-69x2-rg4h-cxfgCGA-8w8p-pqg5-g568CGA-945r-8x66-c83wCGA-9c5m-fpq7-hrg4CGA-c7qq-4h5f-c53cCGA-f7jj-crxf-h3f4CGA-f8h3-r43v-6rv6CGA-g2pr-3px2-hh9hCGA-gxvm-fwp4-8pwwCGA-hfr6-wv34-5wccCGA-j5jw-hf4r-rq39CGA-jw35-27vj-qh35CGA-mgfx-q4rg-cgpwCGA-mgp6-c6vp-39j7CGA-mr5h-f5j9-rw8gCGA-mr84-cmqx-xj7gCGA-p7r8-f98v-8pwxCGA-q3qp-c5w4-782mCGA-qhjq-hmg9-v44cCGA-qmf4-7fmm-9mfrCGA-r22q-q3j6-2p5xCGA-rxvm-x3mv-fvq5CGA-v89j-w9mf-2rhqCGA-vgf2-7g95-jq99CGA-vm8j-ch62-rq5xCGA-vwmg-x463-wxp5CGA-w5fp-2j4w-2m96CGA-w7r9-vrg8-qwg7CGA-w8fg-j4xj-xc9rCGA-x569-c4hq-mq8qCGA-3823-6rfh-qp57CGA-hvh4-fm8v-jxv5CGA-3vjr-xpwp-2f86CGA-37wr-27rq-r37pCGA-4cvc-f3hf-f9j3CGA-j3cv-7r56-6hccCGA-xmgp-522c-6cqpCGA-3wrh-h439-c3g7CGA-mpgh-cjj3-8mh6
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 29 Jul 2026, 16:32
Last modified:29 Jul 2026, 17:53

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (nvd)
EPSS Score
0.46% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jul 2026, 16:32
Published
Vulnerability first disclosed
29 Jul 2026, 17:53
Last Modified
Vulnerability information updated

Description

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a different caller with the same cache key, disclosing private response bodies and headers including Set-Cookie. Separately, a Cache-Control header that combines an unqualified private directive with a qualified one triggers an uncaught TypeError in the cache-control parser, which rejects the request and, depending on the consumer's error handling, can terminate the process. Both issues affect applications using the cache interceptor in shared mode, including the default configuration. The issues are fixed in undici 7.29.0 and 8.9.0.

CVSS Metrics

  • v3.1HIGHScore: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS Trends

Current EPSS score: 0.46% Percentile: 39%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • CWE-248Uncaught Exception

    An exception is thrown from a function, but it is not caught.

  • CWE-525Use of Web Browser Cache Containing Sensitive Information

    The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.

Affected Systems

  • chainguardcode-server

    < 4.130.0-r5

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardkibana-9.1

    all

  • chainguardkibana-9.1-iamguarded

    all

  • chainguardkibana-9.2

    < 9.2.8-r19

  • chainguardkibana-9.2-iamguarded

    < 9.2.8-r19

  • chainguardkibana-9.3

    all

  • chainguardkibana-9.3-iamguarded

    all

  • chainguardlangfuse-3

    < 3.225.0-r3

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.225.0-r3

  • chainguardlangfuse-4

    < 4.3.1-r3

  • chainguardlangfuse-4-worker

    < 4.3.1-r3

  • chainguardlangfuse-fips-3

    < 3.224.3-r9

  • chainguardlangfuse-fips-3-worker

    < 3.224.3-r9

  • chainguardlangfuse-fips-4

    < 4.4.0-r0

  • chainguardlangfuse-fips-4-worker

    < 4.4.0-r0

  • chainguardpelias-api

    < 7.8.0-r7

  • chainguardrenovate

    < 44.11.4-r0 | < 44.11.3-r0

  • chainguardvitess-24

    < 24.0.2-r10

  • chainguardvitess-24-compat

    < 24.0.3-r7

  • wolficode-server

    < 4.130.0-r5

  • wolfilangfuse-3

    < 3.225.0-r3

  • wolfilangfuse-3-compat

    < 3.225.7-r6

  • wolfilangfuse-3-worker

    < 3.225.0-r3

  • wolfirenovate

    < 44.11.4-r0 | < 44.11.3-r0

  • wolfivitess-24

    < 24.0.2-r10

  • wolfivitess-24-compat

    < 24.0.3-r7

  • debiannode-undici

    all | all | < 8.9.0+dfsg+~cs3.2.0-1

  • ubuntunode-undici

    all | all

  • nodejsundici

    ≥ 7.0.0, < 7.29.0 | ≥ 8.0.0, < 8.9.0

  • Npmundici

    ≥ 7.0.0, < 7.29.0 | ≥ 8.0.0, < 8.9.0

  • undiciundici

    ≥ 7.0.0, < 7.29.0 | ≥ 8.0.0, < 8.9.0

References (11)