
Upwind Security MDR@UpwindMDR
🚨High - http-cache-semantics Cache Isolation Bypass via max-stale (CVE-2026-93748) http-cache-semantics <= 4.2.0 mishandles client Cache-Control: max-stale when evaluating security-zeroed shared-cache entries. An unauthenticated attacker can request the same URL with an oversized max-stale to force reuse of another user’s cached response, potentially exposing Set-Cookie session credentials. 👉Affected: http-cache-semantics <= 4.2.0
0000020
304 followersView on X
