Medium · 6.0 Node.js & npm GHSA-ch52-4w7c-c8xp CVE-2026-93748
http-cache-semantics: Cross-User Cache Disclosure via max-stale Directive (CVE-2026-93748)
A flaw in http-cache-semantics (through version 4.2.0) allows unauthenticated attackers to retrieve other users' cached responses, including session cookies, by sending crafted max-stale requests. No fix is currently available.
AI summary
A vulnerability has been disclosed in http-cache-semantics, a widely used npm library for implementing HTTP caching rules. Tracked as CVE-2026-93748, the issue allows an unauthenticated attacker to retrieve cached responses belonging to other users by manipulating the client's max-stale directive. Because this can expose session cookies stored in shared caches, the issue carries meaningful risk for applications relying on this library for cache validation. No fixed version is currently available.
What Happened
A security researcher or advisory process identified that http-cache-semantics fails to properly validate cache entries that were deliberately zeroed for security purposes when it processes a client's max-stale directive. By requesting the same URL with a large max-stale value, an attacker can cause the library to serve a cached response intended for a different user, including sensitive data such as Set-Cookie session credentials, from shared-cache entries.
Technical Cause
The vulnerability is classified as CWE-524, Use of Cache Containing Sensitive Information. The root cause lies in how http-cache-semantics handles max-stale directive processing in combination with cache entries that have been security-zeroed. This validation gap means stale, zeroed cache entries can still be returned to a requester who did not originate the cached response, bypassing the intended security control that should have prevented reuse.
Why It Matters
The flaw allows retrieval of another user's cached data, specifically including session cookies, without requiring authentication or user interaction. In environments using shared caching layers, this could allow an attacker to hijack another user's session by obtaining their Set-Cookie credentials simply by issuing requests with a manipulated max-stale value against the same URL.
Who Is Affected
Any application or service using the http-cache-semantics npm package in versions up to and including 4.2.0, particularly those deployed behind or alongside shared caching infrastructure where cache entries from multiple users could be commingled, is potentially affected.
Affected Versions
All versions of http-cache-semantics from the initial release (version 0) through version 4.2.0 are affected, according to the published advisory.
Fixes and Mitigation
At the time of publication, no fixed version of http-cache-semantics has been listed in the advisory data. Organizations should monitor the GitHub Advisory Database (GHSA-ch52-4w7c-c8xp) and NVD entry for CVE-2026-93748 for updates on a vendor patch. Until a fix is released, consider auditing shared-cache deployments that rely on this library and evaluate whether max-stale handling can be restricted or disabled at the caching layer as a temporary mitigation.
Recommended Action
Review your dependency tree for http-cache-semantics and determine whether your deployment uses shared caching that could expose cross-user responses. Since no official fix is currently available, apply compensating controls where possible, such as restricting or validating max-stale values at your caching proxy, and monitor the advisory for a patched release before continuing to rely on default max-stale handling in shared-cache scenarios.
PatchBriefing score
6.0 / 10 · Medium
Official CVSS: 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
This issue received a PatchBriefing score of 6 out of 10. The CVSS 4.0 base score of 8.7 reflects high confidentiality impact combined with network-based, low-complexity, no-privilege-required, no-user-interaction exploitation conditions, which contributed the largest portion of the score. Additional contributions came from the unauthenticated remote attack vector, the lack of required user interaction, and the absence of an available fix, each adding incremental risk. No evidence of known exploitation, public exploit code, or EPSS-based likelihood data was available, which limited the overall score despite the high base CVSS rating.
Affected versions
- http-cache-semantics <= 4.2.0
- vulnerable
Reported fixes
At the time of publication, no fixed version of http-cache-semantics has been listed in the advisory data. Organizations should monitor the GitHub Advisory Database (GHSA-ch52-4w7c-c8xp) and NVD entry for CVE-2026-93748 for updates on a vendor patch. Until a fix is released, consider auditing shared-cache deployments that rely on this library and evaluate whether max-stale handling can be restricted or disabled at the caching layer as a temporary mitigation.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email