Junglewise Threat Intelligence

CVE-2026-93748: http-cache-semantics improper cache validation with max-stale directive

CVE-2026-93748 · Severity: high · CVSS 7.5 · Published 2026-09-18

Executive brief

http-cache-semantics is a JavaScript library that implements HTTP caching logic per RFC 7234. A vulnerability allows attackers to retrieve cached responses (including session cookies) from other users by exploiting improper validation of security-zeroed cache entries when processing client max-stale directives. In shared cache environments, this could lead to account takeover or session hijacking.

Technical details

The library fails to properly validate security-zeroed cache entries when processing HTTP Cache-Control max-stale directives, allowing unauthenticated attackers to retrieve stale cached responses belonging to other users. An attacker can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were intentionally zeroed for security. The vulnerability affects the cache semantics validation logic in the JavaScript implementation.

Affected products

  • Kornelski http-cache-semantics through 4.2.0

Timeline

  • 2026-09-18: disclosed: CVE-2026-93748 published

References

Related threats