VYPR

http-cache-semantics

by Kornelski

CVEs (2)

  • CVE-2026-93748HigSep 18, 2026
    risk 0.49cvss 7.5epss

    http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large…

  • CVE-2026-93750MedSep 18, 2026
    risk 0.38cvss 5.9epss

    http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive…