CWE-524
Use of Cache Containing Sensitive Information
Description
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-204
CVEs mapped to this weakness (71)
page 3 of 4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-64648 | Med | 0.28 | 5.4 | 0.00 | Jul 27, 2026 | Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body.… | ||
| CVE-2024-33004 | Med | 0.28 | 4.3 | 0.00 | May 14, 2024 | SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited… | ||
| CVE-2024-0874 | Med | 0.28 | 5.3 | 0.01 | Apr 25, 2024 | A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching. | ||
| CVE-2019-14997 | Med | 0.28 | 4.3 | 0.01 | Sep 11, 2019 | The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with… | ||
| CVE-2026-40012 | — | Med | 0.27 | 5.3 | 0.00 | Jun 25, 2026 | ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled; | |
| CVE-2026-32244 | Med | 0.27 | 5.3 | 0.00 | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in… | ||
| CVE-2026-44457 | Med | 0.27 | 5.3 | 0.00 | May 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one… | ||
| CVE-2026-24472 | Med | 0.27 | 5.3 | 0.00 | Jan 27, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard… | ||
| CVE-2024-49580 | Med | 0.27 | 5.3 | 0.00 | Oct 17, 2024 | In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure | ||
| CVE-2023-45696 | Med | 0.26 | 4.0 | 0.00 | Feb 10, 2024 | Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser. | ||
| CVE-2019-11244 | Med | 0.26 | 5.0 | 0.00 | Apr 22, 2019 | In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to… | ||
| CVE-2026-54625 | Med | 0.24 | 4.8 | 0.00 | Aug 20, 2026 | django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site,… | ||
| CVE-2019-9495 | Low | 0.24 | 3.7 | 0.03 | Apr 17, 2019 | The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary… | ||
| CVE-2022-3292 | Med | 0.23 | 4.6 | 0.01 | Sep 28, 2022 | Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8. | ||
| CVE-2026-6907 | Med | 0.21 | 4.3 | 0.00 | May 5, 2026 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported… | ||
| CVE-2026-27205 | Med | 0.21 | 4.3 | 0.00 | Feb 21, 2026 | Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs… | ||
| CVE-2025-64696 | Low | 0.21 | 3.3 | 0.00 | Dec 9, 2025 | Android App "Brother iPrint&Scan" versions 6.13.7 and earlier improperly uses an external cache directory. If exploited, application-specific files may be accessed from other malicious applications. | ||
| CVE-2025-65681 | Low | 0.21 | 3.3 | 0.00 | Nov 26, 2025 | An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. | ||
| CVE-2023-37517 | Low | 0.21 | 3.2 | 0.00 | Apr 30, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. | ||
| CVE-2024-30127 | Low | 0.21 | 3.2 | 0.00 | Apr 24, 2025 | Missing "no cache" headers in HCL Leap permits sensitive data to be cached. |
- risk 0.28cvss 5.4epss 0.00
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body.…
- risk 0.28cvss 4.3epss 0.00
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited…
- risk 0.28cvss 5.3epss 0.01
A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
- risk 0.28cvss 4.3epss 0.01
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a reverse Proxy and or a load balancer with…
- risk 0.27cvss 5.3epss 0.00
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
- risk 0.27cvss 5.3epss 0.00
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in…
- risk 0.27cvss 5.3epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one…
- risk 0.27cvss 5.3epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard…
- risk 0.27cvss 5.3epss 0.00
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
- risk 0.26cvss 4.0epss 0.00
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
- risk 0.26cvss 5.0epss 0.00
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to…
- risk 0.24cvss 4.8epss 0.00
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site,…
- risk 0.24cvss 3.7epss 0.03
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary…
- risk 0.23cvss 4.6epss 0.01
Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- risk 0.21cvss 4.3epss 0.00
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being stored and served. Earlier, unsupported…
- risk 0.21cvss 4.3epss 0.00
Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs…
- risk 0.21cvss 3.3epss 0.00
Android App "Brother iPrint&Scan" versions 6.13.7 and earlier improperly uses an external cache directory. If exploited, application-specific files may be accessed from other malicious applications.
- risk 0.21cvss 3.3epss 0.00
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks.
- risk 0.21cvss 3.2epss 0.00
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
- risk 0.21cvss 3.2epss 0.00
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.