Description
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross-User Cache Disclosure
Action: Patch
AI Analysis

Impact

The http-cache-semantics library fails to correctly validate security-zeroed cache entries when it parses client max‑stale directives, enabling unauthenticated attackers to obtain cached responses that belong to other users. By requesting the same URL with a large max‑stale value, an attacker can retrieve another user’s Set‑Cookie session credentials from shared‑cache entries that were intentionally zeroed for security reasons. This results in unauthorized disclosure of privileged session data, allowing the attacker to impersonate legitimate users or gain additional access.

Affected Systems

The vulnerability affects the kornelski:http-cache-semantics product, specifically versions up to and including 4.2.0.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score of less than 1% suggests that while exploitation is technically possible, it is expected to occur infrequently. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the weakness remotely by sending crafted HTTP requests containing a large max‑stale value; the request must target a host that uses the affected library and is reachable by the attacker. The lack of authentication requirements lowers the barrier for exploitation, though the attacker requires network access to the vulnerable service.

Generated by OpenCVE AI on September 19, 2026 at 16:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade http-cache-semantics to the latest stable release that contains the fix for CVE‑2026‑93748.
  • Reconfigure the caching layer to either reject max‑stale directives or to enforce strict validation of security‑zeroed entries before serving cached content.
  • Ensure that privileged data such as session cookies are not stored in shared caches or that caches are segmented per user to prevent cross‑user data leakage.

Generated by OpenCVE AI on September 19, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-ch52-4w7c-c8xp http-cache-semantics max-stale handling can disclose cross-user cached responses
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.
Title http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale
First Time appeared Http-cache-semantics Project
Http-cache-semantics Project http-cache-semantics
Weaknesses CWE-524
CPEs cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:*
Vendors & Products Http-cache-semantics Project
Http-cache-semantics Project http-cache-semantics
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Http-cache-semantics Project Http-cache-semantics
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:07.274Z

Reserved: 2026-09-18T16:30:17.085Z

Link: CVE-2026-93748

cve-icon Vulnrichment

Updated: 2026-09-18T20:04:44.166Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:18:33.330

Modified: 2026-09-23T17:17:49.593

Link: CVE-2026-93748

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T17:51:34Z

Links: CVE-2026-93748 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses
  • CWE-524

    Use of Cache Containing Sensitive Information