Executive brief
http-cache-semantics is a JavaScript library that implements HTTP caching rules according to RFC 7234. A validation flaw in the _varyMatches() function fails to properly handle Vary header wildcards, allowing attackers to retrieve cached responses intended for other clients and expose sensitive user data across different sessions.
Technical details
The _varyMatches() function performs byte-for-byte string comparison when validating Vary header wildcards, failing to implement proper HTTP semantics for header matching. This allows an attacker to craft requests that bypass cache validation logic and retrieve cached responses meant for different users. The vulnerability is exploitable via network requests without requiring authentication or user interaction.
Affected products
- Kornelski http-cache-semantics through 4.2.0
Timeline
- 2026-09-18: disclosed