Matteo Collina[verified]@matteocollinaDisclosure
The post announces CVE‑2026‑9679, detailing how percent‑decoded characters can inject into Set‑Cookie headers to cause session fixation, open redirects, and cache poisoning, but it offers no PoC, exploit, or patch information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
CVE-2026-9679 is identified as an HTTP Response Header Injection vulnerability in the Undici Cookie Parser using percent-decoding; no PoC, exploit, patch, or active exploitation details are provided.
Infoflowcloud@infoflowcloudGeneral
The post lists CVE-2026‑9679, describing the affected module and decoding behavior, but offers no proof of exploitation, tools, or remediation steps.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑9679, noting that undici’s cookie parser incorrectly percent‑decodes cookie values, potentially leading to injection vulnerabilities. No proof‑of‑concept, active exploitation, or patch details are provided.
Ulises Gascón@kom_256Patch
The advisory announces a medium‑severity security fix for CVE‑2026‑9679 affecting undici, specifying the vulnerability as an HTTP header injection via percent‑decoded Set‑Cookie headers, and lists the patched versions.