Disclosure summary
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-ch52-4w7c-c8xp
Open original source · Updated Oct 02, 2026
http-cache-semantics max-stale handling can disclose cross-user cached responses
Source severity: HIGH / 8.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | http-cache-semantics | Not supplied |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-18T14:31:44-04:00
MODIFIED 2026-10-02T18:36:44-04:00
INGESTED 2026-10-06T11:45:17-04:00