CVE-2026-11525 | undici up to 6.25.x/7.27.x/8.4.x Cookies Feature permissive list of allowed inputs (GHSA-g8m3-5g58-fq7m / EUVD-2026-37758)
A vulnerability was found in undici up to 6.25.x/7.27.x/8.4.x. It has been declared as problematic. This impacts an unknown function of the component Cookies Feature. The manipulation results in permissive list of allowed inputs.
This vulnerability is cataloged as CVE-2026-11525. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.