HIGHnpm

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

CVE-2026-13697Published 2 days agoUpdated 1 day agoSource: OSV

Affected packages

  • undici

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.31%
EPSS percentile
23.7%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 24%.

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives | HackTribune