A vulnerability was found in undici up to 6.25.x/7.27.x/8.4.x . It has been declared as problematic . This impacts an unknown function of the component Cookies Feature . The manipulation results in permissive list of allowed inputs. This vulnerability is cataloged as CVE-2026-11525 . The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.