OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-93748 (CVSS 8.7)

NVD · officialPublished Sep 18, 2026Risk 37/100EPSS 0.4%

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.

CVSS
8.7
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source