CWE-525
CVEs classified under CWE-525, newest first.
4 CVEsRSS
CVE-2026-13697High· 7.4undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
▾ Twilightundici · undiciEPSS 0.46%via GHSA
GHSA-6vgg-xhvh-38ffLownebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
nebula-mesh: POST /api/v1/hosts/{id}/mobile-bundle response lacks Cache-Control: no-store
▾ Sunlitjuev · github.com/juev/nebula-meshvia GHSA
CVE-2025-36364Medium· 6.2IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.
▾ Sunlithcltech · devops_planEPSS 0.10%via NVD
CVE-2024-22349Medium· 4.0IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.
▾ Sunlithcltech · devops_velocityEPSS 0.21%via NVD