Bug 2538846 (CVE-2026-93750) - CVE-2026-93750 http-cache-semantics: http-cache-semantics: Information disclosure via improper Vary header wildcard validation
Summary: CVE-2026-93750 http-cache-semantics: http-cache-semantics: Information disclo...
Keywords:
Status: NEW
Alias: CVE-2026-93750
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 20:53 UTC by OSIDB Bzimport
Modified: 2026-09-29 15:34 UTC (History)
135 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 20:53:30 UTC
http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.


Note You need to log in before you can comment on or make changes to this bug.