CVE-2026-93748

NameCVE-2026-93748
Descriptionhttp-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148405

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-got (PTS)bookworm11.8.5+~cs58.13.36-3vulnerable
trixie11.8.5+~cs58.13.36-5vulnerable
forky, sid11.8.6+~cs58.13.36-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-gotsource(unstable)(unfixed)1148405

Notes

[trixie] - node-got <no-dsa> (Minor issue)
[bookworm] - node-got <postponed> (Minor issue)
https://github.com/kornelski/http-cache-semantics/issues/56
node-got embeds and provides node-http-cache-semantics

Search for package or bug name: Reporting problems