CVE-2026-85152
highCVSS v3 Base Score
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.2%
Exploitation probability in 30 days
Top 93% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
None
Published: September 4, 2026 (6 days ago)
Last Modified: September 4, 2026
Vendor: Red Hat
Fix Available: ✓ Yes
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in undici. When the cache or deduplicate interceptor is directly composed onto a Client or Pool, the destination origin is omitted from cache and request-deduplication keys. This allows a remote attacker to perform cross-origin cache poisoning, leading to information disclosure and potentially a full authentication bypass. An attacker could exploit this by having a trusted origin accept a malicious token, without contacting the legitimate trusted origin.
CWE
CWE-346Affected Products
Exploit IntelligenceOpenShift PipelinesRed Hat AMQ Broker 7Red Hat Ansible Automation Platform 2Red Hat Build of Podman DesktopRed Hat Developer HubRed Hat Enterprise Linux 10Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9Red Hat Hardened Images