Source: node-got Version: 11.8.5+~cs58.13.36-8 Severity: important Tags: security upstream Forwarded: https://github.com/kornelski/http-cache-semantics/issues/56 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-got. AFAICS, node-got provides the problematic node-http-cache-semantics. No upstream fix exists yet at time of writing. CVE-2026-93748[0]: | http-cache-semantics through 4.2.0 fails to properly validate | security-zeroed cache entries when processing client max-stale | directives, allowing unauthenticated attackers to retrieve cached | responses belonging to other users. Attackers can request the same | URL with a large max-stale value to obtain another user's Set-Cookie | session credentials from shared-cache entries that were deliberately | zeroed for security reasons. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-93748 https://www.cve.org/CVERecord?id=CVE-2026-93748 [1] https://github.com/kornelski/http-cache-semantics/issues/56 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

