Source: node-got Version: 11.8.5+~cs58.13.36-8 Severity: important Tags: security upstream Forwarded: https://github.com/kornelski/http-cache-semantics/issues/57 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-got. node-got provides node-http-cache-semantics. TTBOMK, no upstream fix exists yet at time of writing this bugreport. CVE-2026-93750[0]: | http-cache-semantics through 4.2.0 contains a cache validation | vulnerability in the _varyMatches() function that fails to properly | validate Vary header wildcards due to byte-for-byte string | comparison. Attackers can request URLs previously fetched by other | clients to receive cached responses intended for different users, | disclosing sensitive information across clients. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-93750 https://www.cve.org/CVERecord?id=CVE-2026-93750 [1] https://github.com/kornelski/http-cache-semantics/issues/57 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

