Source: node-got
Version: 11.8.5+~cs58.13.36-8
Severity: important
Tags: security upstream
Forwarded: https://github.com/kornelski/http-cache-semantics/issues/56
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for node-got.

AFAICS, node-got provides the problematic node-http-cache-semantics.
No upstream fix exists yet at time of writing.

CVE-2026-93748[0]:
| http-cache-semantics through 4.2.0 fails to properly validate
| security-zeroed cache entries when processing client max-stale
| directives, allowing unauthenticated attackers to retrieve cached
| responses belonging to other users. Attackers can request the same
| URL with a large max-stale value to obtain another user's Set-Cookie
| session credentials from shared-cache entries that were deliberately
| zeroed for security reasons.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93748
    https://www.cve.org/CVERecord?id=CVE-2026-93748
[1] https://github.com/kornelski/http-cache-semantics/issues/56

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to