{"cve":"CVE-2026-93750","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"[0,*]"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"product":"http-cache-semantics","vendor":"http-cache-semantics_project"},{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"generic","value":"[0,4.2.0]"}}],"enrichment":{"confidence":100.0,"confidence_source":"cna","scores":[{"score":100.0,"source":"cna"}]},"original":{"product":"http-cache-semantics","source":"cna","vendor":"kornelski"},"product":"http-cache-semantics","vendor":"kornelski"}],"created":"2026-09-19T16:45:16.795651+00:00","updated":"2026-09-23T02:45:14.070709+00:00","vendors":["http-cache-semantics_project","http-cache-semantics_project$PRODUCT$http-cache-semantics","kornelski","kornelski$PRODUCT$http-cache-semantics"]},"epss":{"score":0.0035},"mitre":{"cpes":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:*"],"created":"2026-09-18T17:51:35.687000+00:00","description":"http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.9,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{"score":8.2,"vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}},"mitre_repo_path":"cves/2026/93xxx/CVE-2026-93750.json","references":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501","https://github.com/kornelski/http-cache-semantics/issues/57","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard"],"title":"http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard","updated":"2026-09-18T18:03:20.270000+00:00","vendors":["http-cache-semantics_project","http-cache-semantics_project$PRODUCT$http-cache-semantics"],"weaknesses":["CWE-436"]},"nvd":{"cpes":[],"created":"2026-09-18T18:18:33.633000+00:00","description":"http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.9,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{"score":8.2,"vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2026/CVE-2026-93750.json","references":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501","https://github.com/kornelski/http-cache-semantics/issues/57","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard"],"title":null,"updated":"2026-09-23T17:17:49.997000+00:00","vendors":[],"weaknesses":["CWE-436"]},"opencve":{"changes":[{"created":"2026-09-18T21:30:00+00:00","data":[{"details":{"new":"http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.","old":null},"type":"description"},{"details":{"new":"http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard","old":null},"type":"title"},{"details":["http-cache-semantics_project","http-cache-semantics_project$PRODUCT$http-cache-semantics"],"type":"first_time"},{"details":{"added":["CWE-436"],"removed":[]},"type":"weaknesses"},{"details":{"added":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["http-cache-semantics_project","http-cache-semantics_project$PRODUCT$http-cache-semantics"],"removed":[]},"type":"vendors"},{"details":{"added":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501","https://github.com/kornelski/http-cache-semantics/issues/57","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":5.9,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{"score":8.2,"vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"c0680253-df05-41f2-bdb4-760d17290d32"},{"created":"2026-09-21T10:45:00+00:00","data":[{"details":["kornelski","kornelski$PRODUCT$http-cache-semantics"],"type":"first_time"},{"details":{"added":["kornelski","kornelski$PRODUCT$http-cache-semantics"],"removed":[]},"type":"vendors"}],"id":"42137470-2859-49b4-91ba-d100a02bd2cb"},{"created":"2026-09-23T00:15:00+00:00","data":[{"details":{"added":["CWE-524"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://nvd.nist.gov/vuln/detail/CVE-2026-93750","https://www.cve.org/CVERecord?id=CVE-2026-93750"],"removed":[]},"type":"references"},{"details":{"added":{},"removed":{},"updated":{"threat_severity":{"new":"Moderate","old":null}}},"type":"metrics"}],"id":"566362f4-e2cf-449c-af89-6e423a0a2164"}],"cpes":{"data":["cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-09-18T17:51:35+00:00","provider":"redhat"},"description":{"data":"http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":5.9,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{"score":8.2,"vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"},"provider":"mitre"},"epss":{"data":{"score":0.0035},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":"Moderate","provider":"redhat"}},"references":{"data":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501","https://github.com/kornelski/http-cache-semantics/issues/57","https://nvd.nist.gov/vuln/detail/CVE-2026-93750","https://www.cve.org/CVERecord?id=CVE-2026-93750","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard"],"providers":["mitre","nvd","redhat","vulnrichment"]},"title":{"data":"http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard","provider":"mitre"},"updated":{"data":"2026-09-21T10:04:10.942695+00:00","provider":"enrichment"},"vendors":{"data":["http-cache-semantics_project","http-cache-semantics_project$PRODUCT$http-cache-semantics","kornelski","kornelski$PRODUCT$http-cache-semantics"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-436","CWE-524"],"providers":["mitre","nvd","redhat"]}},"redhat":{"cpes":[],"created":"2026-09-18T17:51:35+00:00","description":"http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.9,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"threat_severity":"Moderate"},"redhat_repo_path":"2026/CVE-2026-93750.json","references":["https://github.com/kornelski/http-cache-semantics","https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501","https://github.com/kornelski/http-cache-semantics/issues/57","https://nvd.nist.gov/vuln/detail/CVE-2026-93750","https://www.cve.org/CVERecord?id=CVE-2026-93750","https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard"],"title":"http-cache-semantics: http-cache-semantics: Information disclosure via improper Vary header wildcard validation","updated":"2026-09-18T17:51:35+00:00","vendors":[],"weaknesses":["CWE-524"]},"vulnrichment":{"cpes":[],"created":"2026-09-18T17:51:35.687000+00:00","description":"http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":["https://github.com/kornelski/http-cache-semantics/issues/57"],"title":"http-cache-semantics through 4.2.0 Cross-Client Cache Disclosure via Vary Wildcard","updated":"2026-09-18T18:03:16.325000+00:00","vendors":[],"vulnrichment_repo_path":"2026/93xxx/CVE-2026-93750.json","weaknesses":[]}}