#1147405 node-cookies: CVE-2026-88038

Package:
src:node-cookies
Source:
src:node-cookies
Submitter:
Salvatore Bonaccorso
Date:
2026-09-13 16:51:02 UTC
Severity:
normal
Tags:
#1147405#5
Date:
2026-09-11 15:13:57 UTC
From:
To:
Hi,

The following vulnerability was published for node-cookies.

CVE-2026-88038[0]:
| cookies is a Node.js library for reading and writing HTTP cookies,
| used by Koa via ctx.cookies. In versions before 0.9.2 the library
| validates the cookie name and value against character sets that
| reject the semicolon separator, but the domain and path options are
| checked only against a permissive RFC 7230 field-content matcher
| that allows semicolons, and both are written into the Set-Cookie
| header unescaped. An application that passes untrusted or request-
| derived data into the domain or path option can therefore inject
| additional cookie attributes, overriding SameSite, Secure, HttpOnly,
| or Domain on the cookies the application issues. This is a Set-
| Cookie attribute injection issue (CWE-74). The issue is fixed in
| cookies 0.9.2, which validates domain and path against RFC 6265
| character sets. As a workaround, keep domain and path application-
| set rather than derived from untrusted input.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-88038
https://www.cve.org/CVERecord?id=CVE-2026-88038
[1] https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
[2] https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147405#8
Date:
2026-09-13 16:35:49 UTC
From:
To:
Hello,

Bug #1147405 in node-cookies reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-cookies/-/commit/c08e6edcbc6c5a7f1a15fa7cd94b66009ad569de

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147405

#1147405#13
Date:
2026-09-13 16:35:51 UTC
From:
To:
Hello,

Bug #1147405 in node-cookies reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-cookies/-/commit/c08e6edcbc6c5a7f1a15fa7cd94b66009ad569de

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147405

#1147405#18
Date:
2026-09-13 16:48:50 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-cookies, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147405@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-cookies package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 13 Sep 2026 18:34:23 +0200
Source: node-cookies
Architecture: source
Version: 0.9.2+~0.9.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1147405
Changes:
 node-cookies (0.9.2+~0.9.2-1) unstable; urgency=medium
 .
   * Team upload
   * Declare compliance with policy 4.7.4
   * New upstream  version (Closes: #1147405, CVE-2026-88038)
Checksums-Sha1:
 0fb0ce9069bfc33a8897904247e1fcd05755c6d5 2468 node-cookies_0.9.2+~0.9.2-1.dsc
 ccdf86d782f2dea34531dd32733a25be48177cd4 3314 node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz
 668d97be6aa7a58507deebce2261d60238c2d4e8 19364 node-cookies_0.9.2+~0.9.2.orig.tar.gz
 2465e01b6432114c09f4c839e43c8a8b9205e240 3288 node-cookies_0.9.2+~0.9.2-1.debian.tar.xz
Checksums-Sha256:
 a6972895401e7000314a9c77448f175e036ce98f0dca5b184b995b6aaba9b8ee 2468 node-cookies_0.9.2+~0.9.2-1.dsc
 233b1c8c2bb475053e92a4c9c8781c28064c637ee612fe31684aa33258b55626 3314 node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz
 e426a41923cd6c36e12c2ad7639576c6072eeaa8131027e1fc238ce12d5ed0bb 19364 node-cookies_0.9.2+~0.9.2.orig.tar.gz
 d3b62d893a6ae3d3aefd90091ea409d2a4ff40ebc931f4cfff8017917807d9fb 3288 node-cookies_0.9.2+~0.9.2-1.debian.tar.xz
Files:
 f985bd7fc01e7508d97be2fcbfceecae 2468 javascript optional node-cookies_0.9.2+~0.9.2-1.dsc
 45a3d88e00bdf1fc85bf518e3a27e26f 3314 javascript optional node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz
 9ff003f44e3dd848694bac595e395dd7 19364 javascript optional node-cookies_0.9.2+~0.9.2.orig.tar.gz
 5f4871f37e1e55e913f2d5cfa233ff8b 3288 javascript optional node-cookies_0.9.2+~0.9.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqm0M0ACgkQ9tdMp8mZ
7umt2A//RdhP7fUrRkNlrpX+x5dFX7Qd3/o2SkI3awBanSYGDc9xwQXhlCcQ9pdV
eKxLFAhVVzJ0JjWCExw3575YSfoEWUuHB5iMmlT7/kUIFdRwXDfVBHxDZa+Vw8hG
V5GZxBzp5It0Gb3LJXP8IlcndKUYQ32eg8q0CVCB4v8A+TvBSYL0Tp/iX6+gDNZA
ypwb7KGw7mIgr8bJLaI2GTjXK7hdu1VTxlpyR4dOsIgVy0+pY5LwEOUueP8kd1Ns
XYlYgMRBXKSxIhMlylQXX+y01dte9FDnHv90lqIQAOoyWcNQWjtw3KI3Lr5E8uoE
4pVZScEoRBnYrOdDMWG3L9/Xy8A9Ang5IZKqjh5Py1jp18i7pEPHoZM8SjfN5e0Z
Ej082cN1/UnERxV8NYhZ1kXarJeJvUSyL6QdtR0QHAfp9CzZwzJ8bolYptukcyQ2
nPTGu5vuLyHUdTj7nh4Cmb5mTZmbvibXGxazXJxAPj4OPyIPhJFFodGi4pYSDUcO
jXtSn3dJSwyl6DAUYX0Gj2rXC+z8NAVcgD0Su93PZUVf7MMU9adcDlaF7TqMiCc2
tVb8cfCN9biDE6OGIYLOsTou8iO1tm4L54V4IIH5X8GnkbhreB9G+Yu8QPvLFw0V
zGfHUkDx77h2oUorzIDgZSP3RM0W0qLKPwG0nYSGPdskXs886z8=
=lcEi
-----END PGP SIGNATURE-----