CVE-2026-93750

NameCVE-2026-93750
Descriptionhttp-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1148406

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-got (PTS)bookworm11.8.5+~cs58.13.36-3vulnerable
trixie11.8.5+~cs58.13.36-5vulnerable
forky, sid11.8.6+~cs58.13.36-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-gotsource(unstable)(unfixed)1148406

Notes

[trixie] - node-got <no-dsa> (Minor issue)
[bookworm] - node-got <postponed> (Minor issue)
https://github.com/kornelski/http-cache-semantics/issues/57
node-got embeds and provides node-http-cache-semantics

Search for package or bug name: Reporting problems