Interpretation Conflict in http-cache-semantics
CVE-2026-93750
- http-cache-semantics
- org.webjars.npm:http-cache-semantics
Summary
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the "_varyMatches()" function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.
- HIGH
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-436 - Interpretation Conflict
Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.
Advisory Timeline
- Published