Vulnerability GHSA-ch52-4w7c-c8xp
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
14 days ago
September 18, 2026 at 06:31 PM UTC
http-cache-semantics max-stale handling can disclose cross-user cached responses
1.0.0 - 4.2.0
1.0.0 - 4.2.0
Summary
http-cache-semantics max-stale handling can disclose cross-user cached responses
Details
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Impacted packages
Timeline
Published
14 days ago
September 18, 2026 at 06:31 PM UTC
Last Modified
1 hour ago
October 02, 2026 at 10:45 PM UTC