node-undici (8.9.0+dfsg+~cs3.2.0-1)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/js-team/node-undici.git
-
- Branch: master
- Path: debian/changelog
- Repo size: 5246976
- Browser: https://salsa.debian.org/js-team/node-undici
- Last scan: 2026-08-08 19:22:04+00
- Error: https://salsa.debian.org/api/v4/projects/js-team%2Fnode-undici API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
- Next scan: 2026-08-16 09:36:00+00
- Debian changelog in Git:
node-undici (8.9.0+dfsg+~cs3.2.0-1) unstable; urgency=medium
* New upstream version 8.9.0+dfsg+~cs3.2.0
Fixes the following vulnerabilities:
+ CVE-2026-13697 (High): cross-user information disclosure and
parse-time crash via degenerate private cache directives.
Closes: #1143070
+ CVE-2026-14643 (Medium): optional whitespace around = in qualified
no-cache and private directives could bypass shared-cache
restrictions and disclose authenticated data across users.
+ CVE 2026-15157 (Medium): a malicious type property on a duck-typed
blob-like HTTP/1.1 request body could inject CRLF sequences into the
generated content-type header.
+ CVE-2026-16728 (Medium): the retry interceptor could expose a stale
Content-Length after resuming a partial response, potentially causing
downstream response desynchronization, hangs, or corruption.
+ CVE-2026-16729 (Medium): unsanitized domain and unparsed values passed
to setCookie() could inject cookie attributes.
Closes: #1143063
-- Jérémy Lal <kapouer@melix.org> Thu, 30 Jul 2026 15:40:51 +0200
- This branch is even with tag debian/8.9.0+dfsg+_cs3.2.0-1