Junglewise Threat Intelligence

CVE-2026-93750: http-cache-semantics Vary header validation bypass

CVE-2026-93750 · Severity: medium · CVSS 5.9 · Published 2026-09-18

Executive brief

http-cache-semantics is a JavaScript library that implements HTTP caching rules according to RFC 7234. A validation flaw in the _varyMatches() function fails to properly handle Vary header wildcards, allowing attackers to retrieve cached responses intended for other clients and expose sensitive user data across different sessions.

Technical details

The _varyMatches() function performs byte-for-byte string comparison when validating Vary header wildcards, failing to implement proper HTTP semantics for header matching. This allows an attacker to craft requests that bypass cache validation logic and retrieve cached responses meant for different users. The vulnerability is exploitable via network requests without requiring authentication or user interaction.

Affected products

  • Kornelski http-cache-semantics through 4.2.0

Timeline

  • 2026-09-18: disclosed

References

Related threats