Impact
The http-cache-semantics library fails to correctly validate security-zeroed cache entries when it parses client max‑stale directives, enabling unauthenticated attackers to obtain cached responses that belong to other users. By requesting the same URL with a large max‑stale value, an attacker can retrieve another user’s Set‑Cookie session credentials from shared‑cache entries that were intentionally zeroed for security reasons. This results in unauthorized disclosure of privileged session data, allowing the attacker to impersonate legitimate users or gain additional access.
Affected Systems
The vulnerability affects the kornelski:http-cache-semantics product, specifically versions up to and including 4.2.0.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that while exploitation is technically possible, it is expected to occur infrequently. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the weakness remotely by sending crafted HTTP requests containing a large max‑stale value; the request must target a host that uses the affected library and is reachable by the attacker. The lack of authentication requirements lowers the barrier for exploitation, though the attacker requires network access to the vulnerable service.
OpenCVE Enrichment
Github GHSA