CVE-2026-93748: http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale

Published Sep 18, 2026
·
Updated

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.

Affected Software

1 affected component
npm/http-cache-semantics<=4.2.0

Event History

Sep 18, 2026
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments using http-cache-semantics through 4.2.0 in a shared-cache context are exposed if cached responses for different users can be served for the same URL. The impact described involves disclosure of another user's Set-Cookie session credentials from security-zeroed shared-cache entries.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction. They can request the same URL with a large max-stale directive in an attempt to retrieve another user's cached response.

3

Is confidentiality, integrity, or availability affected?

The supplied severity vector indicates high confidentiality impact, with no integrity or availability impact. The disclosed data may include Set-Cookie session credentials belonging to another user.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203