VulnSea

CWE-524

CVEs classified under CWE-524, newest first.

27 CVEsRSS

CVE-2026-93748High· 7.5PoC
4d ago

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers …

Midnightkornelski · http-cache-semanticsEPSS 0.40%via NVD
CVE-2026-89186Medium· 6.3
6d ago

Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-contr…

Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-contr…

SunlitZenHive · mppEPSS 0.39%via NVD
CVE-2026-91992Medium· 5.9PoC
1w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

Twilighttornadoweb · tornadoEPSS 0.21%via NVD
CVE-2026-89639Medium· 5.5⚖ disputed
1w ago

kernel: cifs: use cifs_invalidate_cache() in cifs_do_truncate() for O_TRUNC (CVE-2026-89639)

A flaw was found in the Linux kernel's Common Internet File System (CIFS) implementation. When a file is truncated, the `cifs_do_truncate()` function does not properly invalidate the file system cache (fscache). This oversight can lead to …

SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.12%via CSAF
CVE-2026-88059Medium· 4.0
1w ago

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authentic…

Sunlitangular · angularEPSS 0.30%via CVEORG
CVE-2026-19625Medium· 5.3⚖ disputed
2w ago

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

SunlitIBM · Enterprise Build of QuarkusEPSS 0.31%via NVD
CVE-2026-82755Medium· 6.3
2w ago

Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728…

Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients. The RFC 8414 and RFC 9728…

Sunlitash-project · ash_authentication_oauth2_serverEPSS 0.37%via NVD
CVE-2026-84933Medium· 6.5
2w ago

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that…

Sunlitnodejs · undiciEPSS 0.25%via NVD
CVE-2026-54625Medium· 4.8
1mo ago

django CMS is a content management system powered by Django

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key funct…

Sunlitdjango-cms · django-cmsEPSS 0.15%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

Twilightgeolens · geolensvia GHSA
CVE-2026-59903Medium· 6.5PoC
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…

Twilightnetty · io.netty:netty-codec-httpEPSS 0.24%via NVD
CVE-2026-71316High· 7.5
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and page guards because import.meta.prerender is no…

Twilightnuxt · nuxtEPSS 0.30%via NVD
CVE-2026-14643Medium· 5.9
1mo ago

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

Sunlitundici · undiciEPSS 0.30%via GHSA
CVE-2026-59213Low· 3.5
2mo ago

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVE-2026-64648Medium
2mo ago

Next.js: Cache confusion of response bodies for requests with bodies

Next.js: Cache confusion of response bodies for requests with bodies

Sunlitnext · nextEPSS 0.34%via GHSA
CVE-2026-61836High· 8.6
2mo ago

Directus: Authorization-dependent response served from unsegmented cache key

Directus: Authorization-dependent response served from unsegmented cache key

Twilightdirectus · directusEPSS 0.47%via GHSA
CVE-2026-49858Medium· 5.9
2mo ago

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate

Sunlitapi-platform · api-platform/coreEPSS 0.32%via GHSA
CVE-2026-0281High· 7.1
2mo ago

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens

An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first…

Twilightpaloaltonetworks · pan-osEPSS 0.28%via NVD
CVE-2026-53943Critical· 9.6
2mo ago

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header

Midnightghost · ghostEPSS 0.45%via GHSA
CVE-2026-9678Medium· 5.9
3mo ago

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

Sunlitundici · undiciEPSS 0.39%via GHSA
CVE-2026-50169Medium
3mo ago

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Sunlitangular · @angular/service-workerEPSS 0.23%via GHSA
CVE-2026-50170High
3mo ago

@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache

@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache

Twilightangular · @angular/commonEPSS 0.43%via GHSA
CVE-2026-50184Medium
3mo ago

@angular/service-worker: Request Credential & Cache Policy Stripping

@angular/service-worker: Request Credential & Cache Policy Stripping

Sunlitangular · @angular/service-workerEPSS 0.21%via GHSA
CVE-2026-41841Medium· 5.9
3mo ago

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3…

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3…

Sunlitvmware · spring_frameworkEPSS 0.34%via NVD
CVE-2026-46309High· 7.0
3mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise Add validation in xe_vm_madvise_ioctl() to reject PAT indices with XE_COH_NONE coherency mode w…

In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise Add validation in xe_vm_madvise_ioctl() to reject PAT indices with XE_COH_NONE coherency mode w…

TwilightEPSS 0.13%via NVD
CVE-2026-35172High· 7.5PoC
5mo ago

Distribution is a toolkit to pack, ship, store, and deliver container content

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: t…

Midnightdistribution · distributionEPSS 0.46%via NVD
CVE-2025-9901Medium· 5.9
1y ago

A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses

A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authen…

SunlitEPSS 0.46%via NVD
CWE-524 vulnerabilities (CVEs) · VulnSea