- Package:
- src:node-cookies
- Source:
- src:node-cookies
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-13 16:51:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for node-cookies. CVE-2026-88038[0]: | cookies is a Node.js library for reading and writing HTTP cookies, | used by Koa via ctx.cookies. In versions before 0.9.2 the library | validates the cookie name and value against character sets that | reject the semicolon separator, but the domain and path options are | checked only against a permissive RFC 7230 field-content matcher | that allows semicolons, and both are written into the Set-Cookie | header unescaped. An application that passes untrusted or request- | derived data into the domain or path option can therefore inject | additional cookie attributes, overriding SameSite, Secure, HttpOnly, | or Domain on the cookies the application issues. This is a Set- | Cookie attribute injection issue (CWE-74). The issue is fixed in | cookies 0.9.2, which validates domain and path against RFC 6265 | character sets. As a workaround, keep domain and path application- | set rather than derived from untrusted input. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-88038 https://www.cve.org/CVERecord?id=CVE-2026-88038 [1] https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf [2] https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1147405 in node-cookies reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-cookies/-/commit/c08e6edcbc6c5a7f1a15fa7cd94b66009ad569de (this message was generated automatically) -- Greetings https://bugs.debian.org/1147405
Hello, Bug #1147405 in node-cookies reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-cookies/-/commit/c08e6edcbc6c5a7f1a15fa7cd94b66009ad569de (this message was generated automatically) -- Greetings https://bugs.debian.org/1147405
We believe that the bug you reported is fixed in the latest version of node-cookies, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1147405@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-cookies package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sun, 13 Sep 2026 18:34:23 +0200 Source: node-cookies Architecture: source Version: 0.9.2+~0.9.2-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1147405 Changes: node-cookies (0.9.2+~0.9.2-1) unstable; urgency=medium . * Team upload * Declare compliance with policy 4.7.4 * New upstream version (Closes: #1147405, CVE-2026-88038) Checksums-Sha1: 0fb0ce9069bfc33a8897904247e1fcd05755c6d5 2468 node-cookies_0.9.2+~0.9.2-1.dsc ccdf86d782f2dea34531dd32733a25be48177cd4 3314 node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz 668d97be6aa7a58507deebce2261d60238c2d4e8 19364 node-cookies_0.9.2+~0.9.2.orig.tar.gz 2465e01b6432114c09f4c839e43c8a8b9205e240 3288 node-cookies_0.9.2+~0.9.2-1.debian.tar.xz Checksums-Sha256: a6972895401e7000314a9c77448f175e036ce98f0dca5b184b995b6aaba9b8ee 2468 node-cookies_0.9.2+~0.9.2-1.dsc 233b1c8c2bb475053e92a4c9c8781c28064c637ee612fe31684aa33258b55626 3314 node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz e426a41923cd6c36e12c2ad7639576c6072eeaa8131027e1fc238ce12d5ed0bb 19364 node-cookies_0.9.2+~0.9.2.orig.tar.gz d3b62d893a6ae3d3aefd90091ea409d2a4ff40ebc931f4cfff8017917807d9fb 3288 node-cookies_0.9.2+~0.9.2-1.debian.tar.xz Files: f985bd7fc01e7508d97be2fcbfceecae 2468 javascript optional node-cookies_0.9.2+~0.9.2-1.dsc 45a3d88e00bdf1fc85bf518e3a27e26f 3314 javascript optional node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz 9ff003f44e3dd848694bac595e395dd7 19364 javascript optional node-cookies_0.9.2+~0.9.2.orig.tar.gz 5f4871f37e1e55e913f2d5cfa233ff8b 3288 javascript optional node-cookies_0.9.2+~0.9.2-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqm0M0ACgkQ9tdMp8mZ 7umt2A//RdhP7fUrRkNlrpX+x5dFX7Qd3/o2SkI3awBanSYGDc9xwQXhlCcQ9pdV eKxLFAhVVzJ0JjWCExw3575YSfoEWUuHB5iMmlT7/kUIFdRwXDfVBHxDZa+Vw8hG V5GZxBzp5It0Gb3LJXP8IlcndKUYQ32eg8q0CVCB4v8A+TvBSYL0Tp/iX6+gDNZA ypwb7KGw7mIgr8bJLaI2GTjXK7hdu1VTxlpyR4dOsIgVy0+pY5LwEOUueP8kd1Ns XYlYgMRBXKSxIhMlylQXX+y01dte9FDnHv90lqIQAOoyWcNQWjtw3KI3Lr5E8uoE 4pVZScEoRBnYrOdDMWG3L9/Xy8A9Ang5IZKqjh5Py1jp18i7pEPHoZM8SjfN5e0Z Ej082cN1/UnERxV8NYhZ1kXarJeJvUSyL6QdtR0QHAfp9CzZwzJ8bolYptukcyQ2 nPTGu5vuLyHUdTj7nh4Cmb5mTZmbvibXGxazXJxAPj4OPyIPhJFFodGi4pYSDUcO jXtSn3dJSwyl6DAUYX0Gj2rXC+z8NAVcgD0Su93PZUVf7MMU9adcDlaF7TqMiCc2 tVb8cfCN9biDE6OGIYLOsTou8iO1tm4L54V4IIH5X8GnkbhreB9G+Yu8QPvLFw0V zGfHUkDx77h2oUorzIDgZSP3RM0W0qLKPwG0nYSGPdskXs886z8= =lcEi -----END PGP SIGNATURE-----