CVE-2026-14643

Aliases:UBUNTU-CVE-2026-14643DEBIAN-CVE-2026-14643GHSA-jr45-8vmc-qm54CGA-3368-mqmv-7v6qCGA-52x3-vj66-x458CGA-6x3g-f485-m6jqCGA-8669-6v7x-8q4wCGA-86mw-8hq4-5vf9CGA-94pr-g5m2-5j93CGA-9fh7-f4cf-hj98CGA-fqqw-w8rf-6mh4CGA-hc5r-rv24-rqg7CGA-pj8c-7xwr-8rj5CGA-pwpc-736j-m244CGA-2463-c9vq-v5q5CGA-2475-p7gh-9cwwCGA-298f-fwmc-fhgfCGA-2gj4-xqq8-7xr8CGA-2vj8-pf84-2wffCGA-4q7h-8569-jmh5CGA-5xqc-53w8-mmf4CGA-842r-x9h9-v59mCGA-86p6-36pw-8746CGA-89h5-rxr4-f7wjCGA-99hp-jqx2-3q2pCGA-9f4c-8w8v-9vfqCGA-9mc2-5qxw-78f8CGA-f357-fc3h-mmqmCGA-fh3w-mjj9-7xwwCGA-gjfj-f535-j7wwCGA-hmvr-h29h-x66cCGA-hxmp-4jrh-xhcpCGA-mff3-3r9p-c8f5CGA-mjhx-4v6r-xqc9CGA-mp2p-jmjx-w64rCGA-mq7q-3663-vp3jCGA-mv77-9cpv-hcpcCGA-pmr4-ch9q-282jCGA-prvr-3gwx-r94gCGA-qc6x-pxh3-q86qCGA-qj32-xrv4-6fvhCGA-qr9f-59j8-5f59CGA-rh9f-m73f-9xchCGA-vqg5-f94j-f5v7CGA-vwcv-rfgf-qjw2CGA-w9r7-3g8j-jm9vCGA-wq2w-7m59-75c7CGA-xgvv-2hph-8wvmCGA-xr4x-gxmx-c2rhCGA-7f2q-hmcr-ggx9CGA-xcwq-6rr2-rmx9CGA-3v44-c455-72xcCGA-7wxh-w4v2-2297CGA-v23h-7j44-37hwCGA-c5fx-vv6g-gj2cCGA-c7hm-68vr-4r57CGA-h3gx-wc5v-mvpwCGA-hhpj-cg8q-ch25CGA-2qw2-hwfc-6wq9CGA-m2q5-9h69-29c7
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 29 Jul 2026, 21:08
Last modified:30 Jul 2026, 15:18

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.3% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

29 Jul 2026, 21:08
Published
Vulnerability first disclosed
30 Jul 2026, 15:18
Last Modified
Vulnerability information updated

Description

undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so the cache decision fails to recognize the qualification and the response is stored. In shared-cache mode, this lets a response containing one user's authenticated data be served from cache to a later caller, including an unauthenticated one, when both requests resolve to the same cache key. It affects applications that enable the cache interceptor in shared mode, forward Authorization headers upstream, and receive cacheable responses with qualified directives padded with whitespace around the equals sign. This is the whitespace-around-equals variant that the fix for CVE-2026-9678 did not normalize, and it is fixed in undici 7.29.0 and 8.9.0.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.30% Percentile: 23%

Techniques & Countermeasures

  • CWE-436Interpretation Conflict

    Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

  • CWE-524Use of Cache Containing Sensitive Information

    The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Systems

  • chainguardcode-server

    < 4.130.0-r5

  • chainguardcommercial-gitlab-rails-ee-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-19.3

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.1

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.2

    all

  • chainguardcommercial-gitlab-rails-ee-fips-19.3

    all

  • chainguardkibana-9.1

    all

  • chainguardkibana-9.1-iamguarded

    all

  • chainguardkibana-9.2

    < 9.2.8-r19

  • chainguardkibana-9.2-iamguarded

    < 9.2.8-r19

  • chainguardkibana-9.3

    all

  • chainguardkibana-9.3-iamguarded

    all

  • chainguardlangfuse-3

    < 3.225.0-r3

  • chainguardlangfuse-3-compat

    < 3.225.7-r6

  • chainguardlangfuse-3-worker

    < 3.225.0-r3

  • chainguardlangfuse-4

    < 4.3.1-r3

  • chainguardlangfuse-4-worker

    < 4.3.1-r3

  • chainguardlangfuse-fips-3

    < 3.224.3-r9

  • chainguardlangfuse-fips-3-worker

    < 3.224.3-r9

  • chainguardlangfuse-fips-4

    < 4.4.0-r0

  • chainguardlangfuse-fips-4-worker

    < 4.4.0-r0

  • chainguardpelias-api

    < 7.8.0-r7

  • chainguardrenovate

    < 44.11.4-r0 | < 44.11.3-r0

  • chainguardvitess-24

    < 24.0.2-r10

  • chainguardvitess-24-compat

    < 24.0.3-r7

  • wolficode-server

    < 4.130.0-r5

  • wolfilangfuse-3

    < 3.225.0-r3

  • wolfilangfuse-3-compat

    < 3.225.7-r6

  • wolfilangfuse-3-worker

    < 3.225.0-r3

  • wolfirenovate

    < 44.11.4-r0 | < 44.11.3-r0

  • wolfivitess-24

    < 24.0.2-r10

  • wolfivitess-24-compat

    < 24.0.3-r7

  • debiannode-undici

    all | all | < 8.9.0+dfsg+~cs3.2.0-1

  • ubuntunode-undici

    all | all

  • nodejsundici

    ≥ 7.0.0, < 7.29.0 | ≥ 8.0.0, < 8.9.0

  • Npmundici

    ≥ 7.0.0, < 7.29.0 | ≥ 8.0.0, < 8.9.0

  • undiciundici

    ≥ 7.0.0, < 7.29.0 | ≥ 8.0.0, < 8.9.0

References (12)