← All advisoriesModerate severity5.9NVD Advisory· Published Jun 17, 2026undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingCVE-2026-9679Descriptionundici: undici vulnerable to HTTP header injection via Set-Cookie percent-decodingAffected products1Undici/Undicillm-fuzzyPatchesVulnerability mechanicsAI mechanics synthesis has not run for this CVE yet.News mentions0No linked articles in our index yet.