DEBIAN-CVE-2026-93750

Source
https://security-tracker.debian.org/tracker/CVE-2026-93750
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-93750.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-93750
Upstream
  • CVE-2026-93750
Published
2026-09-18T18:18:33Z
Modified
2026-09-19T05:00:30Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients.

References

Affected packages

Debian:12 / node-got

Package

Name
node-got
Purl
pkg:deb/debian/node-got?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.8.5+~cs58.13.36-3
11.8.5+~cs58.13.36-4
11.8.5+~cs58.13.36-5
11.8.5+~cs58.13.36-6
11.8.5+~cs58.13.36-7
11.8.5+~cs58.13.36-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-93750.json"

Debian:13 / node-got

Package

Name
node-got
Purl
pkg:deb/debian/node-got?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.8.5+~cs58.13.36-5
11.8.5+~cs58.13.36-6
11.8.5+~cs58.13.36-7
11.8.5+~cs58.13.36-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-93750.json"

Debian:14 / node-got

Package

Name
node-got
Purl
pkg:deb/debian/node-got?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

11.*
11.8.5+~cs58.13.36-5
11.8.5+~cs58.13.36-6
11.8.5+~cs58.13.36-7
11.8.5+~cs58.13.36-8

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-93750.json"