A vulnerability categorized as problematic has been discovered in nodejs undici up to 6.27.x/7.28.x/8.8.x. Impacted is the function
setCookie of the component Cookie Sanitization. Such manipulation of the argument domain/unparsed leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-16729. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.