Skip to main content

Interpretation Conflict in http-cache-semantics

CVE-2026-93750

  • http-cache-semantics
  • org.webjars.npm:http-cache-semantics
Severity High
Score 8.2/10

Summary

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the "_varyMatches()" function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-436 - Interpretation Conflict

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Advisory Timeline

  • Published