cve-2026-93750
MEDIUM CVSS 5.9 csaf_redhat
Description
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
Timeline
- Published
- 2026-09-18 17:51 UTC
- Last Modified
- 2026-09-22
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"aggregate_severity": {
"namespace": "https://access.redhat.com/security/updates/classification/",
"text": "Moderate"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright © Red Hat, Inc. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "legal_disclaimer",
"text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
"title": "Terms of Use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://access.redhat.com/security/team/contact/",
"issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
"name": "Red Hat Product Security",
"namespace": "https://www.redhat.com"
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-93750.json"
}
],
"title": "http-cache-semantics: http-cache-semantics: Information disclosure via improper Vary header wildcard validation",
"tracking": {
"current_release_date": "2026-09-22T22:26:36+00:00",
"generator": {
"date": "2026-09-22T22:26:36+00:00",
"engine": {
"name": "Red Hat SDEngine",
"version": "5.4.0"
}
},
"id": "CVE-2026-93750",
"initial_release_date": "2026-09-18T17:51:35.687000+00:00",
"revision_history": [
{
"date": "2026-09-18T17:51:35.687000+00:00",
"number": "1",
"summary": "Initial version"
},
{
"date": "2026-09-22T20:58:56+00:00",
"number": "2",
"summary": "Current version"
},
{
"date": "2026-09-22T22:26:36+00:00",
"number": "3",
"summary": "Last generated version"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Red Hat Hardened Images",
"product": {
"name": "Red Hat Hardened Images",
"product_id": "red_hat_hardened_images",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:hummingbird:1"
}
}
}
],
"category": "product_family",
"name": "Red Hat Hardened Images"
},
{
"category": "product_version",
"name": "dotnet10.0.src",
"product": {
"name": "dotnet10.0.src",
"product_id": "dotnet10.0.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/dotnet10.0@10.0.112-1.hum1?arch=src"
}
}
},
{
"category": "product_version",
"name": "dotnet8.0.src",
"product": {
"name": "dotnet8.0.src",
"product_id": "dotnet8.0.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/dotnet8.0@8.0.130-0.1.hum1?arch=src"
}
}
},
{
"category": "product_version",
"name": "dotnet9.0.src",
"product": {
"name": "dotnet9.0.src",
"product_id": "dotnet9.0.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/dotnet9.0@9.0.119-2.hum1?arch=src"
}
}
},
{
"category": "product_version",
"name": "grafana12.4.src",
"product": {
"name": "grafana12.4.src",
"product_id": "grafana12.4.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/grafana12.4@12.4.10-0.6.hum1?arch=src"
}
}
},
{
"category": "product_version",
"name": "grafana13.1.src",
"product": {
"name": "grafana13.1.src",
"product_id": "grafana13.1.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/grafana13.1@13.1.6-0.2.hum1?arch=src"
}
}
},
{
"category": "product_version",
"name": "grafana13.2.src",
"product": {
"name": "grafana13.2.src",
"product_id": "grafana13.2.src",
"product_identification_helper": {
"purl": "pkg:rpm/redhat/grafana13.2@13.2.1-0.5.hum1?arch=src"
}
}
}
],
"category": "vendor",
"name": "Red Hat"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "dotnet10.0.src as a component of Red Hat Hardened Images",
"product_id": "red_hat_hardened_images:dotnet10.0.src"
},
"product_reference": "dotnet10.0.src",
"relates_to_product_reference": "red_hat_hardened_images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "dotnet8.0.src as a component of Red Hat Hardened Images",
"product_id": "red_hat_hardened_images:dotnet8.0.src"
},
"product_reference": "dotnet8.0.src",
"relates_to_product_reference": "red_hat_hardened_images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "dotnet9.0.src as a component of Red Hat Hardened Images",
"product_id": "red_hat_hardened_images:dotnet9.0.src"
},
"product_reference": "dotnet9.0.src",
"relates_to_product_reference": "red_hat_hardened_images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "grafana12.4.src as a component of Red Hat Hardened Images",
"product_id": "red_hat_hardened_images:grafana12.4.src"
},
"product_reference": "grafana12.4.src",
"relates_to_product_reference": "red_hat_hardened_images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "grafana13.1.src as a component of Red Hat Hardened Images",
"product_id": "red_hat_hardened_images:grafana13.1.src"
},
"product_reference": "grafana13.1.src",
"relates_to_product_reference": "red_hat_hardened_images"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "grafana13.2.src as a component of Red Hat Hardened Images",
"product_id": "red_hat_hardened_images:grafana13.2.src"
},
"product_reference": "grafana13.2.src",
"relates_to_product_reference": "red_hat_hardened_images"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-93750",
"cwe": {
"id": "CWE-524",
"name": "Use of Cache Containing Sensitive Information"
},
"discovery_date": "2026-09-22T20:52:32.322098+00:00",
"ids": [
{
"system_name": "Red Hat Bugzilla ID",
"text": "2538846"
}
],
"notes": [
{
"category": "description",
"text": "A flaw was found in http-cache-semantics. This vulnerability allows a remote attacker to disclose sensitive information across clients. The _varyMatches() function fails to properly validate Vary header wildcards, enabling an attacker to request URLs previously fetched by other clients and receive cached responses intended for different users. This leads to unauthorized information disclosure.",
"title": "Vulnerability description"
},
{
"category": "summary",
"text": "http-cache-semantics: http-cache-semantics: Information disclosure via improper Vary header wildcard validation",
"title": "Vulnerability summary"
},
{
"category": "general",
"text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
"title": "CVSS score applicability"
}
],
"product_status": {
"known_affected": [
"red_hat_hardened_images:dotnet10.0.src",
"red_hat_hardened_images:dotnet8.0.src",
"red_hat_hardened_images:dotnet9.0.src",
"red_hat_hardened_images:grafana12.4.src",
"red_hat_hardened_images:grafana13.1.src",
"red_hat_hardened_images:grafana13.2.src"
]
},
"references": [
{
"category": "self",
"summary": "Canonical URL",
"url": "https://access.redhat.com/security/cve/CVE-2026-93750"
},
{
"category": "external",
"summary": "RHBZ#2538846",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2538846"
},
{
"category": "external",
"summary": "https://www.cve.org/CVERecord?id=CVE-2026-93750",
"url": "https://www.cve.org/CVERecord?id=CVE-2026-93750"
},
{
"category": "external",
"summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-93750",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-93750"
},
{
"category": "external",
"summary": "https://github.com/kornelski/http-cache-semantics",
"url": "https://github.com/kornelski/http-cache-semantics"
},
{
"category": "external",
"summary": "https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501",
"url": "https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L483-L501"
},
{
"category": "external",
"summary": "https://github.com/kornelski/http-cache-semantics/issues/57",
"url": "https://github.com/kornelski/http-cache-semantics/issues/57"
},
{
"category": "external",
"summary": "https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard",
"url": "https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-client-cache-disclosure-via-vary-wildcard"
}
],
"release_date": "2026-09-18T17:51:35.687000+00:00",
"remediations": [
{
"category": "none_available",
"details": "Affected",
"product_ids": [
"red_hat_hardened_images:dotnet10.0.src",
"red_hat_hardened_images:dotnet8.0.src",
"red_hat_hardened_images:dotnet9.0.src",
"red_hat_hardened_images:grafana12.4.src",
"red_hat_hardened_images:grafana13.1.src",
"red_hat_hardened_images:grafana13.2.src"
]
}
],
"scores": [
{
"cvss_v3": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"red_hat_hardened_images:dotnet10.0.src",
"red_hat_hardened_images:dotnet8.0.src",
"red_hat_hardened_images:dotnet9.0.src",
"red_hat_hardened_images:grafana12.4.src",
"red_hat_hardened_images:grafana13.1.src",
"red_hat_hardened_images:grafana13.2.src"
]
}
],
"threats": [
{
"category": "impact",
"details": "Moderate",
"product_ids": [
"red_hat_hardened_images:dotnet10.0.src",
"red_hat_hardened_images:dotnet8.0.src",
"red_hat_hardened_images:dotnet9.0.src",
"red_hat_hardened_images:grafana12.4.src",
"red_hat_hardened_images:grafana13.1.src",
"red_hat_hardened_images:grafana13.2.src"
]
}
],
"title": "http-cache-semantics: http-cache-semantics: Information disclosure via improper Vary header wildcard validation"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)