CWE-524
AllowedUse of Cache Containing Sensitive Information
Abstraction: Base · Status: Incomplete
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
129 vulnerabilities reference this CWE, most recent first.
CVE-2026-103004 (GCVE-0-2026-103004)
Vulnerability from cvelistv5 – Published: 2026-10-01 14:50 – Updated: 2026-10-01 16:09- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/vercel/next.js/security/adviso… | x_refsource_CONFIRM |
| https://github.com/vercel/next.js/releases/tag/v16.3.8 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103004",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T16:09:43.511822Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T16:09:53.178Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "next.js",
"vendor": "vercel",
"versions": [
{
"status": "affected",
"version": "\u003c 16.3.8"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With Cache Components enabled (cacheComponents: true), a \u0027use cache\u0027 function that calls another \u0027use cache\u0027 function that reads a root param can be keyed incorrectly when the inner call is served from an existing entry: the enclosing function\u0027s cache key then omits that root param. The enclosing entry is written once and reused for all root param values, so a response for one root param value can serve content produced for a different value \u2014 whether the page is prerendered at build time or at runtime, or rendered dynamically. Shared cache headers let downstream caches redistribute the content further.\n\nWhat values are leaked cannot be attacker controlled. Which value\u0027s content is served depends only on which invocation wrote the entry first.\n\nThis has been patched in 16.3.8."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:50:27.033Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/vercel/next.js/security/advisories/GHSA-h694-7cp9-m8p3",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/vercel/next.js/security/advisories/GHSA-h694-7cp9-m8p3"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v16.3.8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
}
],
"source": {
"advisory": "GHSA-h694-7cp9-m8p3",
"discovery": "UNKNOWN"
},
"title": "next.js cache leak on warm `use cache` handlers accessing root param"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-103004",
"datePublished": "2026-10-01T14:50:27.033Z",
"dateReserved": "2026-09-29T20:46:08.335Z",
"dateUpdated": "2026-10-01T16:09:53.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94544 (GCVE-0-2026-94544)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:14 – Updated: 2026-10-02 15:14- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/vercel/next.js/security/adviso… | x_refsource_CONFIRM |
| https://github.com/vercel/next.js/commit/bd9214f9… | x_refsource_MISC |
| https://github.com/vercel/next.js/releases/tag/v16.3.8 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "next.js",
"vendor": "vercel",
"versions": [
{
"status": "affected",
"version": "\u003e= 16.3.0, \u003c 16.3.8"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular request can receive unauthenticated unpublished content from an editor\u0027s Draft Mode fill, while an overlapping Draft Mode request can receive published content from a regular fill. When the regular request prerenders a page, the draft-dependent content can persist in the generated page and be served to later visitors until revalidation. Sites are affected when Cache Components or experimental.useCache is enabled and cached functions return draft-dependent content. This issue is fixed in version 16.3.8."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:14:43.506Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/vercel/next.js/security/advisories/GHSA-3w37-wq28-93x7",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/vercel/next.js/security/advisories/GHSA-3w37-wq28-93x7"
},
{
"name": "https://github.com/vercel/next.js/commit/bd9214f9a32854a011bf5fe58e481dffe1bbf598",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/commit/bd9214f9a32854a011bf5fe58e481dffe1bbf598"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v16.3.8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
}
],
"source": {
"advisory": "GHSA-3w37-wq28-93x7",
"discovery": "UNKNOWN"
},
"title": "Next.js: Pending `use cache` fill can leak Draft Mode content into regular responses and persisted pages"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-94544",
"datePublished": "2026-10-02T15:14:43.506Z",
"dateReserved": "2026-09-21T19:21:33.371Z",
"dateUpdated": "2026-10-02T15:14:43.506Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94543 (GCVE-0-2026-94543)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:16 – Updated: 2026-10-02 15:16- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/vercel/next.js/security/adviso… | x_refsource_CONFIRM |
| https://github.com/vercel/next.js/commit/52c94abd… | x_refsource_MISC |
| https://github.com/vercel/next.js/commit/719e4c67… | x_refsource_MISC |
| https://github.com/vercel/next.js/releases/tag/v15.5.27 | x_refsource_MISC |
| https://github.com/vercel/next.js/releases/tag/v16.3.8 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "next.js",
"vendor": "vercel",
"versions": [
{
"status": "affected",
"version": "\u003e= 15.0.0, \u003c 15.5.27"
},
{
"status": "affected",
"version": "\u003e= 16.0.0, \u003c 16.3.8"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated or Incremental Static Regeneration pages can key a response cache entry without sufficiently binding it to the source route. A request can replace one page\u0027s cache entry with content from a different route, causing the affected page to serve incorrect content to every visitor until revalidation. Applications deployed on Vercel are not affected. This issue is fixed in versions 15.5.27 and 16.3.8."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:16:49.658Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/vercel/next.js/security/advisories/GHSA-4jqv-mc3x-m676"
},
{
"name": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
},
{
"name": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v15.5.27",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v16.3.8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
}
],
"source": {
"advisory": "GHSA-4jqv-mc3x-m676",
"discovery": "UNKNOWN"
},
"title": "Next.js: Cache poisoning of SSG and ISR pages in self-hosted Next.js applications"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-94543",
"datePublished": "2026-10-02T15:16:49.658Z",
"dateReserved": "2026-09-21T19:21:33.371Z",
"dateUpdated": "2026-10-02T15:16:49.658Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94484 (GCVE-0-2026-94484)
Vulnerability from cvelistv5 – Published: 2026-10-02 15:26 – Updated: 2026-10-02 15:26- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/vercel/next.js/security/adviso… | x_refsource_CONFIRM |
| https://github.com/vercel/next.js/commit/52c94abd… | x_refsource_MISC |
| https://github.com/vercel/next.js/commit/719e4c67… | x_refsource_MISC |
| https://github.com/vercel/next.js/releases/tag/v15.5.27 | x_refsource_MISC |
| https://github.com/vercel/next.js/releases/tag/v16.3.8 | x_refsource_MISC |
{
"containers": {
"cna": {
"affected": [
{
"product": "next.js",
"vendor": "vercel",
"versions": [
{
"status": "affected",
"version": "\u003e= 15.0.0, \u003c 15.5.27"
},
{
"status": "affected",
"version": "\u003e= 16.0.0, \u003c 16.3.8"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared response cache key that is insufficiently scoped to the source route. A single unauthenticated crafted request can poison that cache, causing cross-user content substitution or persistent denial of service until the poisoned entry is revalidated or replaced. This issue is fixed in versions 15.5.27 and 16.3.8."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T15:26:48.417Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/vercel/next.js/security/advisories/GHSA-mcj8-r9mp-w47p",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/vercel/next.js/security/advisories/GHSA-mcj8-r9mp-w47p"
},
{
"name": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/commit/52c94abdd2ea5f416f5e8353ea8a2edd3fe311b8"
},
{
"name": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/commit/719e4c67d6e92df60246f95e1d96e2dd60789a52"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v15.5.27",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v15.5.27"
},
{
"name": "https://github.com/vercel/next.js/releases/tag/v16.3.8",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/vercel/next.js/releases/tag/v16.3.8"
}
],
"source": {
"advisory": "GHSA-mcj8-r9mp-w47p",
"discovery": "UNKNOWN"
},
"title": "Next.js: Cache poisoning in Next.js SSG/ISR rendering leads to cross-user content substitution and persistent denial of service"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-94484",
"datePublished": "2026-10-02T15:26:48.417Z",
"dateReserved": "2026-09-21T17:25:42.292Z",
"dateUpdated": "2026-10-02T15:26:48.417Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93748 (GCVE-0-2026-93748)
Vulnerability from cvelistv5 – Published: 2026-09-18 17:51 – Updated: 2026-09-24 14:23- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/kornelski/http-cache-semantics… | issue-tracking |
| https://github.com/kornelski/http-cache-semantics | product |
| https://github.com/kornelski/http-cache-semantics… | technical-description |
| https://github.com/kornelski/http-cache-semantics… | technical-description |
| https://www.vulncheck.com/advisories/http-cache-s… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| kornelski | http-cache-semantics |
Affected:
0 , ≤ 4.2.0
(semver)
cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93748",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:05:06.835112Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T20:05:12.650Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/kornelski/http-cache-semantics/issues/56"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/http-cache-semantics",
"product": "http-cache-semantics",
"vendor": "kornelski",
"versions": [
{
"lessThanOrEqual": "4.2.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:http-cache-semantics_project:http-cache-semantics:*:*:*:*:*:*:*:*",
"versionEndIncluding": "4.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Wayde Shi (PayPal Cyber Security Team)"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user\u0027s Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:23:07.274Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Issue #56",
"tags": [
"issue-tracking"
],
"url": "https://github.com/kornelski/http-cache-semantics/issues/56"
},
{
"tags": [
"product"
],
"url": "https://github.com/kornelski/http-cache-semantics"
},
{
"name": "max-stale stale-serving branch that re-serves a zero-lifetime entry",
"tags": [
"technical-description"
],
"url": "https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L425-L441"
},
{
"name": "maxAge() zeroing for shared Set-Cookie and proxy-revalidate responses",
"tags": [
"technical-description"
],
"url": "https://github.com/kornelski/http-cache-semantics/blob/f01112e954b83cfa8765b633ba880e5e980aa54c/index.js#L603-L623"
},
{
"name": "VulnCheck Advisory: http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/http-cache-semantics-through-4.2.0-cross-user-cache-disclosure-via-max-stale"
}
],
"title": "http-cache-semantics through 4.2.0 Cross-User Cache Disclosure via max-stale",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93748",
"datePublished": "2026-09-18T17:51:34.262Z",
"dateReserved": "2026-09-18T16:30:17.085Z",
"dateUpdated": "2026-09-24T14:23:07.274Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89186 (GCVE-0-2026-89186)
Vulnerability from cvelistv5 – Published: 2026-09-16 08:24 – Updated: 2026-09-16 14:50- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/ZenHive/mpp/security/advisorie… | relatedvendor-advisory |
| https://cna.erlef.org/cves/CVE-2026-89186.html | related |
| https://osv.dev/vulnerability/EEF-CVE-2026-89186 | related |
| https://github.com/ZenHive/mpp/commit/2d4d1d94aae… | related |
| https://github.com/ZenHive/mpp/commit/2fd91a5ecbd… | patch |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89186",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T14:50:34.541725Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T14:50:44.399Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.MPP.Plug\u0027"
],
"packageName": "mpp",
"packageURL": "pkg:hex/mpp",
"product": "mpp",
"programFiles": [
"lib/mpp/plug.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.MPP.Plug\u0027:call/2"
}
],
"repo": "https://github.com/ZenHive/mpp",
"vendor": "ZenHive",
"versions": [
{
"lessThan": "0.16.2",
"status": "affected",
"version": "0.1.0",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.MPP.Plug\u0027"
],
"packageName": "zenhive/mpp",
"packageURL": "pkg:github/zenhive/mpp",
"product": "mpp",
"programFiles": [
"lib/mpp/plug.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.MPP.Plug\u0027:call/2"
}
],
"repo": "https://github.com/ZenHive/mpp",
"vendor": "ZenHive",
"versions": [
{
"lessThan": "2fd91a5ecbd0b0ad2a4ac202b79659e8126dbc0b",
"status": "affected",
"version": "2d4d1d94aae7790ae0623063961adbeef171fa71",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eReachable only where the application mounted behind \u003ccode\u003eMPP.Plug\u003c/code\u003e sets its own \u003ccode\u003eCache-Control\u003c/code\u003e on the paid resource, overriding the \u003ccode\u003eprivate\u003c/code\u003e the library wrote, and a shared HTTP cache (CDN or reverse proxy) sits in front of that route. An application that sets no \u003ccode\u003eCache-Control\u003c/code\u003e of its own keeps the library\u0027s \u003ccode\u003eprivate\u003c/code\u003e and is not affected.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Reachable only where the application mounted behind `MPP.Plug` sets its own `Cache-Control` on the paid resource, overriding the `private` the library wrote, and a shared HTTP cache (CDN or reverse proxy) sits in front of that route. An application that sets no `Cache-Control` of its own keeps the library\u0027s `private` and is not affected."
}
],
"value": "Reachable only where the application mounted behind MPP.Plug sets its own Cache-Control on the paid resource, overriding the private the library wrote, and a shared HTTP cache (CDN or reverse proxy) sits in front of that route. An application that sets no Cache-Control of its own keeps the library\u0027s private and is not affected."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ZenHive:mpp:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.16.2",
"versionStartIncluding": "0.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "E.FU"
},
{
"lang": "en",
"type": "remediation developer",
"value": "E.FU"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"dateAssigned": "2026-09-15T15:22:44.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUse of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eMPP.Plug.verify_credential\u003c/code\u003e in \u003ccode\u003elib/mpp/plug.ex\u003c/code\u003e sets \u003ccode\u003epayment-receipt\u003c/code\u003e and \u003ccode\u003ecache-control: private\u003c/code\u003e on the connection before the wrapped application runs, and registers no \u003ccode\u003eregister_before_send/2\u003c/code\u003e callback. \u003ccode\u003ePlug.Conn.put_resp_header/3\u003c/code\u003e replaces an existing header, so a mounting application that sets its own \u003ccode\u003ecache-control\u003c/code\u003e on the paid resource (for example \u003ccode\u003epublic, max-age=3600\u003c/code\u003e) silently overrides the \u003ccode\u003eprivate\u003c/code\u003e the library relies on, and a CDN or reverse proxy can then store the paid 200 together with its \u003ccode\u003ePayment-Receipt\u003c/code\u003e and serve both to unpaid clients. The library-level guarantee is therefore defeatable by the application it protects. For the same reason a downstream non-2xx response still carried \u003ccode\u003ePayment-Receipt\u003c/code\u003e, issuing a receipt for a response that delivered no resource.\u003c/p\u003e\n\u003cp\u003eThis issue affects mpp: from 0.1.0 before 0.16.2.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid.\n\n`MPP.Plug.verify_credential` in `lib/mpp/plug.ex` sets `payment-receipt` and `cache-control: private` on the connection before the wrapped application runs, and registers no `register_before_send/2` callback. `Plug.Conn.put_resp_header/3` replaces an existing header, so a mounting application that sets its own `cache-control` on the paid resource (for example `public, max-age=3600`) silently overrides the `private` the library relies on, and a CDN or reverse proxy can then store the paid 200 together with its `Payment-Receipt` and serve both to unpaid clients. The library-level guarantee is therefore defeatable by the application it protects. For the same reason a downstream non-2xx response still carried `Payment-Receipt`, issuing a receipt for a response that delivered no resource.\n\nThis issue affects mpp: from 0.1.0 before 0.16.2."
}
],
"value": "Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid.\n\nMPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the connection before the wrapped application runs, and registers no register_before_send/2 callback. Plug.Conn.put_resp_header/3 replaces an existing header, so a mounting application that sets its own cache-control on the paid resource (for example public, max-age=3600) silently overrides the private the library relies on, and a CDN or reverse proxy can then store the paid 200 together with its Payment-Receipt and serve both to unpaid clients. The library-level guarantee is therefore defeatable by the application it protects. For the same reason a downstream non-2xx response still carried Payment-Receipt, issuing a receipt for a response that delivered no resource.\n\nThis issue affects mpp: from 0.1.0 before 0.16.2."
}
],
"impacts": [
{
"capecId": "CAPEC-204",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eAn unpaid client requesting the same URL through the shared cache receives the cached paid response, including the \u003ccode\u003ePayment-Receipt\u003c/code\u003e header issued to the paying client. Operators lose the revenue for every cache hit, and the receipt identifying a paid transaction is disclosed to third parties.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "An unpaid client requesting the same URL through the shared cache receives the cached paid response, including the `Payment-Receipt` header issued to the paying client. Operators lose the revenue for every cache hit, and the receipt identifying a paid transaction is disclosed to third parties."
}
],
"value": "An unpaid client requesting the same URL through the shared cache receives the cached paid response, including the Payment-Receipt header issued to the paying client. Operators lose the revenue for every cache hit, and the receipt identifying a paid transaction is disclosed to third parties."
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524 Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T08:24:15.058Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"name": "GitHub Advisory",
"tags": [
"related",
"vendor-advisory"
],
"url": "https://github.com/ZenHive/mpp/security/advisories/GHSA-82qh-vrvm-gqvc"
},
{
"name": "EEF CNA record for CVE-2026-89186",
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-89186.html"
},
{
"name": "OSV record EEF-CVE-2026-89186",
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-89186"
},
{
"name": "Introducing commit 2d4d1d9 in ZenHive/mpp",
"tags": [
"related"
],
"url": "https://github.com/ZenHive/mpp/commit/2d4d1d94aae7790ae0623063961adbeef171fa71"
},
{
"name": "Fix commit 2fd91a5 in ZenHive/mpp",
"tags": [
"patch"
],
"url": "https://github.com/ZenHive/mpp/commit/2fd91a5ecbd0b0ad2a4ac202b79659e8126dbc0b"
}
],
"source": {
"discovery": "INTERNAL"
},
"title": "mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer\u0027s own Cache-Control expose paid responses to shared caches",
"workarounds": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eIn the application mounted behind \u003ccode\u003eMPP.Plug\u003c/code\u003e, stop setting \u003ccode\u003eCache-Control\u003c/code\u003e on paid routes so the library\u0027s \u003ccode\u003eprivate\u003c/code\u003e survives to the response, or set a directive that is itself safe for a shared cache (\u003ccode\u003eprivate\u003c/code\u003e, or \u003ccode\u003eno-store\u003c/code\u003e). Where the application must set its own caching policy, configure the CDN or reverse proxy not to cache responses carrying a \u003ccode\u003ePayment-Receipt\u003c/code\u003e header.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "In the application mounted behind `MPP.Plug`, stop setting `Cache-Control` on paid routes so the library\u0027s `private` survives to the response, or set a directive that is itself safe for a shared cache (`private`, or `no-store`). Where the application must set its own caching policy, configure the CDN or reverse proxy not to cache responses carrying a `Payment-Receipt` header."
}
],
"value": "In the application mounted behind MPP.Plug, stop setting Cache-Control on paid routes so the library\u0027s private survives to the response, or set a directive that is itself safe for a shared cache (private, or no-store). Where the application must set its own caching policy, configure the CDN or reverse proxy not to cache responses carrying a Payment-Receipt header."
}
]
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-89186",
"datePublished": "2026-09-16T08:24:15.058Z",
"dateReserved": "2026-09-11T19:00:02.549Z",
"dateUpdated": "2026-09-16T14:50:44.399Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-88059 (GCVE-0-2026-88059)
Vulnerability from cvelistv5 – Published: 2026-09-10 19:00 – Updated: 2026-09-11 17:50| URL | Tags |
|---|---|
| https://github.com/angular/angular/security/advis… | x_refsource_CONFIRM |
| https://github.com/angular/angular/issues/69777 | x_refsource_MISC |
| https://github.com/angular/angular/pull/69778 | x_refsource_MISC |
| https://github.com/angular/angular/commit/c45028e… | x_refsource_MISC |
| https://github.com/angular/angular/commit/caf6166… | x_refsource_MISC |
| https://github.com/angular/angular/commit/e4c416c… | x_refsource_MISC |
| https://github.com/angular/angular/releases/tag/v… | x_refsource_MISC |
| https://github.com/angular/angular/releases/tag/v… | x_refsource_MISC |
| https://github.com/angular/angular/releases/tag/v22.1.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-88059",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-11T17:49:17.182667Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-11T17:50:22.562Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "angular",
"vendor": "angular",
"versions": [
{
"status": "affected",
"version": "\u003c= 19.2.25"
},
{
"status": "affected",
"version": "\u003e= 20.0.0, \u003c 20.3.28"
},
{
"status": "affected",
"version": "\u003e= 21.0.0, \u003c 21.2.20"
},
{
"status": "affected",
"version": "\u003e= 22.0.0, \u003c 22.1.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular\u0027s @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering (SSR) and hydration use a hierarchical HttpClient configured with withRequestsMadeViaParent. The child TransferCache evaluates an initially anonymous request before delegation, then a parent withInterceptors chain adds an Authorization header, cookie, or API token; although the parent cache skips the authenticated request, the child still stores the private response in TransferState serialized as JSON in the ng-state script. Exploitation requires provideClientHydration, child provideHttpClient delegation through withRequestsMadeViaParent, parent-level credential injection, and an SSR HTML response shared across users by a CDN, reverse proxy, or application cache. A later unauthenticated or unauthorized visitor can receive the cached HTML containing the earlier authenticated user\u0027s sensitive response data. Applications can mitigate by attaching credentials at the child, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML private or no-store. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T19:00:12.376Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/angular/angular/security/advisories/GHSA-p297-fm68-3q8c",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/angular/angular/security/advisories/GHSA-p297-fm68-3q8c"
},
{
"name": "https://github.com/angular/angular/issues/69777",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/issues/69777"
},
{
"name": "https://github.com/angular/angular/pull/69778",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/pull/69778"
},
{
"name": "https://github.com/angular/angular/commit/c45028e44f5f3c1e0006eaccf86642deca51b2af",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/commit/c45028e44f5f3c1e0006eaccf86642deca51b2af"
},
{
"name": "https://github.com/angular/angular/commit/caf616670fd20d528aa69e0131cc17d60f0cc27d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/commit/caf616670fd20d528aa69e0131cc17d60f0cc27d"
},
{
"name": "https://github.com/angular/angular/commit/e4c416c20a1cb222ce73d29c035452b257380c56",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/commit/e4c416c20a1cb222ce73d29c035452b257380c56"
},
{
"name": "https://github.com/angular/angular/releases/tag/v20.3.28",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/releases/tag/v20.3.28"
},
{
"name": "https://github.com/angular/angular/releases/tag/v21.2.20",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/releases/tag/v21.2.20"
},
{
"name": "https://github.com/angular/angular/releases/tag/v22.1.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/angular/angular/releases/tag/v22.1.1"
}
],
"source": {
"advisory": "GHSA-p297-fm68-3q8c",
"discovery": "UNKNOWN"
},
"title": "Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-88059",
"datePublished": "2026-09-10T19:00:12.376Z",
"dateReserved": "2026-09-09T21:22:45.434Z",
"dateUpdated": "2026-09-11T17:50:22.562Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-84933 (GCVE-0-2026-84933)
Vulnerability from cvelistv5 – Published: 2026-09-04 16:59 – Updated: 2026-09-04 18:34{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-84933",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-04T18:34:06.167949Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T18:34:14.407Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/undici",
"product": "undici",
"vendor": "undici",
"versions": [
{
"lessThan": "7.29.1",
"status": "affected",
"version": "7.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.29.1",
"versionType": "semver"
},
{
"lessThan": "8.10.2",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.10.2",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "analyst",
"value": "mcollina"
},
{
"lang": "en",
"type": "remediation reviewer",
"value": "UlisesGascon"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "undici\u0027s cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller\u0027s cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"value": "undici\u0027s cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller\u0027s cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-04T16:59:08.807Z",
"orgId": "ce714d77-add3-4f53-aff5-83d477b104bb",
"shortName": "openjs"
},
"references": [
{
"url": "https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j"
},
{
"url": "https://cna.openjsf.org/security-advisories.html"
}
],
"title": "undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches",
"x_generator": {
"engine": "cve-kit 1.0.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "ce714d77-add3-4f53-aff5-83d477b104bb",
"assignerShortName": "openjs",
"cveId": "CVE-2026-84933",
"datePublished": "2026-09-04T16:59:08.807Z",
"dateReserved": "2026-09-02T16:20:41.850Z",
"dateUpdated": "2026-09-04T18:34:14.407Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82755 (GCVE-0-2026-82755)
Vulnerability from cvelistv5 – Published: 2026-09-07 22:28 – Updated: 2026-09-08 14:42- CWE-524 - Use of Cache Containing Sensitive Information
| URL | Tags |
|---|---|
| https://github.com/ash-project/ash_authentication… | vendor-advisoryrelated |
| https://cna.erlef.org/cves/CVE-2026-82755.html | related |
| https://osv.dev/vulnerability/EEF-CVE-2026-82755 | related |
| https://github.com/ash-project/ash_authentication… | patch |
| Vendor | Product | Version | |
|---|---|---|---|
| ash-project | ash_authentication_oauth2_server |
Affected:
0.1.3 , < 0.3.1
(semver)
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:* |
|
| ash-project | ash_authentication_oauth2_server |
Affected:
99de0a1cacb5ef667c4533278b7c81ca98c00231 , < 768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1
(git)
cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82755",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T14:42:10.746522Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T14:42:17.718Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://repo.hex.pm",
"cpes": [
"cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter\u0027"
],
"packageName": "ash_authentication_oauth2_server",
"packageURL": "pkg:hex/ash_authentication_oauth2_server",
"product": "ash_authentication_oauth2_server",
"programFiles": [
"lib/ash_authentication_phoenix/oauth2_server/protocol_router.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter\u0027:call/2"
}
],
"repo": "https://github.com/ash-project/ash_authentication_oauth2_server",
"vendor": "ash-project",
"versions": [
{
"lessThan": "0.3.1",
"status": "affected",
"version": "0.1.3",
"versionType": "semver"
}
]
},
{
"collectionURL": "https://github.com",
"cpes": [
"cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"modules": [
"\u0027Elixir.AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter\u0027"
],
"packageName": "ash-project/ash_authentication_oauth2_server",
"packageURL": "pkg:github/ash-project/ash_authentication_oauth2_server",
"product": "ash_authentication_oauth2_server",
"programFiles": [
"lib/ash_authentication_phoenix/oauth2_server/protocol_router.ex"
],
"programRoutines": [
{
"name": "\u0027Elixir.AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter\u0027:call/2"
}
],
"repo": "https://github.com/ash-project/ash_authentication_oauth2_server",
"vendor": "ash-project",
"versions": [
{
"lessThan": "768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1",
"status": "affected",
"version": "99de0a1cacb5ef667c4533278b7c81ca98c00231",
"versionType": "git"
}
]
}
],
"configurations": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eReachable only in a multi-tenant deployment where the tenant is derived from outside the request URL (a header or the \u003ccode\u003eHost\u003c/code\u003e) and a shared HTTP cache (CDN, reverse proxy) sits in front of the metadata endpoints.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Reachable only in a multi-tenant deployment where the tenant is derived from outside the request URL (a header or the `Host`) and a shared HTTP cache (CDN, reverse proxy) sits in front of the metadata endpoints."
}
],
"value": "Reachable only in a multi-tenant deployment where the tenant is derived from outside the request URL (a header or the Host) and a shared HTTP cache (CDN, reverse proxy) sits in front of the metadata endpoints."
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ash-project:ash_authentication_oauth2_server:*:*:*:*:*:*:*:*",
"versionEndExcluding": "0.3.1",
"versionStartIncluding": "0.1.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Peter Ullrich"
},
{
"lang": "en",
"type": "reporter",
"value": "Peter Ullrich"
},
{
"lang": "en",
"type": "remediation developer",
"value": "Zach Daniel / Ash Project"
},
{
"lang": "en",
"type": "coordinator",
"value": "Jonatan M\u00e4nnchen / EEF"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eUse of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant\u0027s OAuth discovery metadata to another tenant\u0027s clients.\u003c/p\u003e\n\u003cp\u003eThe RFC 8414 and RFC 9728 metadata endpoints in \u003ccode\u003eAshAuthentication.Phoenix.Oauth2Server.ProtocolRouter\u003c/code\u003e return tenant-specific values (\u003ccode\u003eissuer\u003c/code\u003e, \u003ccode\u003eauthorization_endpoint\u003c/code\u003e, \u003ccode\u003etoken_endpoint\u003c/code\u003e, \u003ccode\u003ejwks_uri\u003c/code\u003e) when a tenant is set, but sent them with \u003ccode\u003eCache-Control: public, max-age=3600\u003c/code\u003e and no \u003ccode\u003eVary\u003c/code\u003e. When the tenant is derived from something other than the URL (a header or the \u003ccode\u003eHost\u003c/code\u003e) and a shared cache sits in front, the cache key is the URL alone, so a stored response for one tenant is served to another for up to an hour. Affected clients may then send authorization codes and secrets to the wrong tenant\u0027s token endpoint and validate tokens against the wrong keys.\u003c/p\u003e\n\u003cp\u003eThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.\u003c/p\u003e"
},
{
"base64": false,
"type": "text/markdown",
"value": "Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant\u0027s OAuth discovery metadata to another tenant\u0027s clients.\n\nThe RFC 8414 and RFC 9728 metadata endpoints in `AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter` return tenant-specific values (`issuer`, `authorization_endpoint`, `token_endpoint`, `jwks_uri`) when a tenant is set, but sent them with `Cache-Control: public, max-age=3600` and no `Vary`. When the tenant is derived from something other than the URL (a header or the `Host`) and a shared cache sits in front, the cache key is the URL alone, so a stored response for one tenant is served to another for up to an hour. Affected clients may then send authorization codes and secrets to the wrong tenant\u0027s token endpoint and validate tokens against the wrong keys.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1."
}
],
"value": "Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant\u0027s OAuth discovery metadata to another tenant\u0027s clients.\n\nThe RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return tenant-specific values (issuer, authorization_endpoint, token_endpoint, jwks_uri) when a tenant is set, but sent them with Cache-Control: public, max-age=3600 and no Vary. When the tenant is derived from something other than the URL (a header or the Host) and a shared cache sits in front, the cache key is the URL alone, so a stored response for one tenant is served to another for up to an hour. Affected clients may then send authorization codes and secrets to the wrong tenant\u0027s token endpoint and validate tokens against the wrong keys.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1."
}
],
"impacts": [
{
"capecId": "CAPEC-204",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-204 Lifting Sensitive Data Embedded in Cache"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524 Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T22:28:24.500Z",
"orgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"shortName": "EEF"
},
"references": [
{
"tags": [
"vendor-advisory",
"related"
],
"url": "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-crqf-7m54-4hgc"
},
{
"tags": [
"related"
],
"url": "https://cna.erlef.org/cves/CVE-2026-82755.html"
},
{
"tags": [
"related"
],
"url": "https://osv.dev/vulnerability/EEF-CVE-2026-82755"
},
{
"tags": [
"patch"
],
"url": "https://github.com/ash-project/ash_authentication_oauth2_server/commit/768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "ash_authentication_oauth2_server serves tenant-specific OAuth metadata as publicly cacheable without Vary, enabling cross-tenant confusion"
}
},
"cveMetadata": {
"assignerOrgId": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
"assignerShortName": "EEF",
"cveId": "CVE-2026-82755",
"datePublished": "2026-09-07T22:28:24.500Z",
"dateReserved": "2026-08-31T01:00:10.817Z",
"dateUpdated": "2026-09-08T14:42:17.718Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-71316 (GCVE-0-2026-71316)
Vulnerability from cvelistv5 – Published: 2026-08-05 21:14 – Updated: 2026-08-06 18:44| URL | Tags |
|---|---|
| https://github.com/nuxt/nuxt/security/advisories/… | x_refsource_CONFIRM |
| https://github.com/nuxt/nuxt/commit/ac9b41a36b622… | x_refsource_MISC |
| https://github.com/nuxt/nuxt/releases/tag/v4.5.1 | x_refsource_MISC |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-71316",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-06T18:39:23.365982Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-06T18:44:45.748Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "nuxt",
"vendor": "nuxt",
"versions": [
{
"status": "affected",
"version": "\u003e= 4.4.0, \u003c 4.5.1"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /\u003cpage\u003e/_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user\u0027s SSR data. This issue is fixed in 4.5.1."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-524",
"description": "CWE-524: Use of Cache Containing Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862: Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T21:14:31.458Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/nuxt/nuxt/security/advisories/GHSA-wm8w-6qjm-cv43"
},
{
"name": "https://github.com/nuxt/nuxt/commit/ac9b41a36b62296a117862254ee7d2b21a2a5203",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nuxt/nuxt/commit/ac9b41a36b62296a117862254ee7d2b21a2a5203"
},
{
"name": "https://github.com/nuxt/nuxt/releases/tag/v4.5.1",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/nuxt/nuxt/releases/tag/v4.5.1"
}
],
"source": {
"advisory": "GHSA-wm8w-6qjm-cv43",
"discovery": "UNKNOWN"
},
"title": "Nuxt runtime payload cache discloses another user\u0027s SSR data across users and to unauthenticated clients"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-71316",
"datePublished": "2026-08-05T21:14:31.458Z",
"dateReserved": "2026-08-05T18:14:42.064Z",
"dateUpdated": "2026-08-06T18:44:45.748Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Protect information stored in cache.
Mitigation
Do not store unnecessarily sensitive information in the cache.
Mitigation
Consider using encryption in the cache.
CAPEC-204: Lifting Sensitive Data Embedded in Cache
An adversary examines a target application's cache, or a browser cache, for sensitive information. Many applications that communicate with remote entities or which perform intensive calculations utilize caches to improve efficiency. However, if the application computes or receives sensitive information and the cache is not appropriately protected, an attacker can browse the cache and retrieve this information. This can result in the disclosure of sensitive information.