CWE-524— Use of Cache Containing Sensitive Information
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.— MITRE CWE catalog
79 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-524page 2 of 2
- CVE-2025-61598MEDIUMCVSS 5.3EG 5.32025-10-28
Discourse is an open source discussion platform. Version before 3.6.2 and 3.6.0.beta2, default Cache-Control response header with value no-store, no-cache was missing from error responses. This may caused unintended caching of those respon…
- CVE-2024-49580MEDIUMCVSS 5.3EG 5.32024-10-17
In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
- CVE-2024-0874MEDIUMCVSS 5.3EG 5.32024-04-25
A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
- CVE-2021-44854MEDIUMCVSS 5.3EG 5.32022-12-26
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis.
- CVE-2025-4233MEDIUMCVSS 5.1EG 5.12025-06-12
An insufficient implementation of cache vulnerability in Palo Alto Networks Prisma® Access Browser enables users to bypass certain data control policies.
- CVE-2026-59213MEDIUMCVSS 5.0EG 5.02026-07-09
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to aiocache key instead of key_builder, cau…
- CVE-2019-11244MEDIUMCVSS 5.0EG 5.02019-04-22
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed a…
- CVE-2026-94484MEDIUMCVSS 4.8EG 4.82026-10-02
Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated or Incremental Static Regeneration routes can use a shared …
- CVE-2026-54625MEDIUMCVSS 4.8EG 4.82026-08-20
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key functio…
- CVE-2024-41906MEDIUMCVSS 4.8EG 4.82024-08-13
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application does not properly handle cacheable HTTP responses in the web service. This could allow an attacker to read a…
- CVE-2022-3292MEDIUMCVSS 4.6EG 4.62022-09-28
Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.
- CVE-2026-107851MEDIUMCVSS 4.3EG 4.32026-10-09
Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the u…
- CVE-2026-6907MEDIUMCVSS 4.3EG 4.32026-05-05
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This can lead to private data being store…
- CVE-2026-27205MEDIUMCVSS 4.3EG 4.32026-02-21
Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Informa…
- CVE-2024-33004MEDIUMCVSS 4.3EG 4.32024-05-14
SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache …
- CVE-2019-14997MEDIUMCVSS 4.3EG 4.32019-09-11
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is configured with a r…
- CVE-2026-94544MEDIUMCVSS 4.2EG 4.22026-10-02
Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without separating Draft Mode requests from regular requests. An overlapping regular reque…
- CVE-2023-45696MEDIUMCVSS 4.0EG 4.02024-02-10
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
- CVE-2026-104006LOWCVSS 3.7EG 3.72026-10-10
The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'comment_author_*, comment_author_email_*' parameter. This makes …
- CVE-2019-9495LOWCVSS 3.7EG 3.72019-04-17
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to instal…
- CVE-2025-64696LOWCVSS 3.3EG 3.32025-12-09
Android App "Brother iPrint&Scan" versions 6.13.7 and earlier improperly uses an external cache directory. If exploited, application-specific files may be accessed from other malicious applications.
- CVE-2025-65681LOWCVSS 3.3EG 3.32025-11-26
An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session…
- CVE-2023-37517LOWCVSS 3.2EG 3.22025-04-30
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
- CVE-2024-30127LOWCVSS 3.2EG 3.22025-04-24
Missing "no cache" headers in HCL Leap permits sensitive data to be cached.
- CVE-2023-37516LOWCVSS 3.2EG 3.22025-04-24
Missing "no cache" headers in HCL Leap permits user directory information to be cached.
- CVE-2026-105752LOWCVSS 3.1EG 3.12026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, Harmony tool continuations submitted through "POST /v1/responses" requests rebuild the next-turn engine input without preserving the cache_salt value, plac…
- CVE-2026-35193LOWCVSS 3.1EG 3.12026-06-03
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requests bearing that header without `Cache-…
- CVE-2026-22741LOWCVSS 3.1EG 3.12026-04-29
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring …
- CVE-2025-43410LOWCVSS 2.4EG 2.42025-12-12
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.2. An attacker with physical access may be able to view deleted notes.
Map vulnerabilities like CWE-524 to your infrastructure
EchelonGraph correlates every CVE — across CWE-524 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →