Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons. | |
| Title | http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale | |
| First Time appeared |
Http-cache-semantics Project
Http-cache-semantics Project http-cache-semantics |
|
| Weaknesses | CWE-524 | |
| CPEs | cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Http-cache-semantics Project
Http-cache-semantics Project http-cache-semantics |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T20:05:12.650Z
Reserved: 2026-09-18T16:30:17.085Z
Link: CVE-2026-93748
Updated: 2026-09-18T20:04:44.166Z
Status : Received
Published: 2026-09-18T18:18:33.330
Modified: 2026-09-18T20:17:33.510
Link: CVE-2026-93748
No data.
OpenCVE Enrichment
No data.
