PT-2026-95590 · Npm · Http-Cache-Semantics

·

CVE-2026-93750

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions http-cache-semantics versions prior to 4.2.1
Description A cache validation issue exists in the varyMatches() function. The function fails to properly validate Vary header wildcards because it uses byte-for-byte string comparison. This allows attackers to request URLs previously fetched by other clients and receive cached responses intended for different users, leading to the disclosure of sensitive information across clients.
Recommendations Update to version 4.2.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103451
AZL-103487
CVE-2026-93750

Affected Products

Http-Cache-Semantics