Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients. | |
| Title | http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard | |
| First Time appeared |
Http-cache-semantics Project
Http-cache-semantics Project http-cache-semantics |
|
| Weaknesses | CWE-436 | |
| CPEs | cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Http-cache-semantics Project
Http-cache-semantics Project http-cache-semantics |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-18T18:03:20.270Z
Reserved: 2026-09-18T16:30:17.776Z
Link: CVE-2026-93750
Updated: 2026-09-18T18:03:16.325Z
Status : Received
Published: 2026-09-18T18:18:33.633
Modified: 2026-09-18T18:18:33.633
Link: CVE-2026-93750
No data.
OpenCVE Enrichment
No data.
