Your message dated Sun, 13 Sep 2026 16:48:50 +0000
with message-id <[email protected]>
and subject line Bug#1147405: fixed in node-cookies 0.9.2+~0.9.2-1
has caused the Debian Bug report #1147405,
regarding node-cookies: CVE-2026-88038
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147405: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147405
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: node-cookies
Version: 0.9.1+~0.9.2-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for node-cookies.
CVE-2026-88038[0]:
| cookies is a Node.js library for reading and writing HTTP cookies,
| used by Koa via ctx.cookies. In versions before 0.9.2 the library
| validates the cookie name and value against character sets that
| reject the semicolon separator, but the domain and path options are
| checked only against a permissive RFC 7230 field-content matcher
| that allows semicolons, and both are written into the Set-Cookie
| header unescaped. An application that passes untrusted or request-
| derived data into the domain or path option can therefore inject
| additional cookie attributes, overriding SameSite, Secure, HttpOnly,
| or Domain on the cookies the application issues. This is a Set-
| Cookie attribute injection issue (CWE-74). The issue is fixed in
| cookies 0.9.2, which validates domain and path against RFC 6265
| character sets. As a workaround, keep domain and path application-
| set rather than derived from untrusted input.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-88038
https://www.cve.org/CVERecord?id=CVE-2026-88038
[1] https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
[2]
https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: node-cookies
Source-Version: 0.9.2+~0.9.2-1
Done: Xavier Guimard <[email protected]>
We believe that the bug you reported is fixed in the latest version of
node-cookies, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <[email protected]> (supplier of updated node-cookies package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 13 Sep 2026 18:34:23 +0200
Source: node-cookies
Architecture: source
Version: 0.9.2+~0.9.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers
<[email protected]>
Changed-By: Xavier Guimard <[email protected]>
Closes: 1147405
Changes:
node-cookies (0.9.2+~0.9.2-1) unstable; urgency=medium
.
* Team upload
* Declare compliance with policy 4.7.4
* New upstream version (Closes: #1147405, CVE-2026-88038)
Checksums-Sha1:
0fb0ce9069bfc33a8897904247e1fcd05755c6d5 2468 node-cookies_0.9.2+~0.9.2-1.dsc
ccdf86d782f2dea34531dd32733a25be48177cd4 3314
node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz
668d97be6aa7a58507deebce2261d60238c2d4e8 19364
node-cookies_0.9.2+~0.9.2.orig.tar.gz
2465e01b6432114c09f4c839e43c8a8b9205e240 3288
node-cookies_0.9.2+~0.9.2-1.debian.tar.xz
Checksums-Sha256:
a6972895401e7000314a9c77448f175e036ce98f0dca5b184b995b6aaba9b8ee 2468
node-cookies_0.9.2+~0.9.2-1.dsc
233b1c8c2bb475053e92a4c9c8781c28064c637ee612fe31684aa33258b55626 3314
node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz
e426a41923cd6c36e12c2ad7639576c6072eeaa8131027e1fc238ce12d5ed0bb 19364
node-cookies_0.9.2+~0.9.2.orig.tar.gz
d3b62d893a6ae3d3aefd90091ea409d2a4ff40ebc931f4cfff8017917807d9fb 3288
node-cookies_0.9.2+~0.9.2-1.debian.tar.xz
Files:
f985bd7fc01e7508d97be2fcbfceecae 2468 javascript optional
node-cookies_0.9.2+~0.9.2-1.dsc
45a3d88e00bdf1fc85bf518e3a27e26f 3314 javascript optional
node-cookies_0.9.2+~0.9.2.orig-types-cookies.tar.gz
9ff003f44e3dd848694bac595e395dd7 19364 javascript optional
node-cookies_0.9.2+~0.9.2.orig.tar.gz
5f4871f37e1e55e913f2d5cfa233ff8b 3288 javascript optional
node-cookies_0.9.2+~0.9.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmqm0M0ACgkQ9tdMp8mZ
7umt2A//RdhP7fUrRkNlrpX+x5dFX7Qd3/o2SkI3awBanSYGDc9xwQXhlCcQ9pdV
eKxLFAhVVzJ0JjWCExw3575YSfoEWUuHB5iMmlT7/kUIFdRwXDfVBHxDZa+Vw8hG
V5GZxBzp5It0Gb3LJXP8IlcndKUYQ32eg8q0CVCB4v8A+TvBSYL0Tp/iX6+gDNZA
ypwb7KGw7mIgr8bJLaI2GTjXK7hdu1VTxlpyR4dOsIgVy0+pY5LwEOUueP8kd1Ns
XYlYgMRBXKSxIhMlylQXX+y01dte9FDnHv90lqIQAOoyWcNQWjtw3KI3Lr5E8uoE
4pVZScEoRBnYrOdDMWG3L9/Xy8A9Ang5IZKqjh5Py1jp18i7pEPHoZM8SjfN5e0Z
Ej082cN1/UnERxV8NYhZ1kXarJeJvUSyL6QdtR0QHAfp9CzZwzJ8bolYptukcyQ2
nPTGu5vuLyHUdTj7nh4Cmb5mTZmbvibXGxazXJxAPj4OPyIPhJFFodGi4pYSDUcO
jXtSn3dJSwyl6DAUYX0Gj2rXC+z8NAVcgD0Su93PZUVf7MMU9adcDlaF7TqMiCc2
tVb8cfCN9biDE6OGIYLOsTou8iO1tm4L54V4IIH5X8GnkbhreB9G+Yu8QPvLFw0V
zGfHUkDx77h2oUorzIDgZSP3RM0W0qLKPwG0nYSGPdskXs886z8=
=lcEi
-----END PGP SIGNATURE-----
pgpgBcliJNGpC.pgp
Description: PGP signature
--- End Message ---