http-cache-semantics
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting http-cache-semanticspage 1 of 1
- CVE-2022-25881MEDIUMCVSS 5.3EG 5.3fixed in 4.1.12023-01-31
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
- CVE-2026-93748HIGHCVSS 7.5EG 7.52026-09-18
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers ca…
Check whether http-cache-semantics is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for http-cache-semantics CVEs against the assets you own.
Book a Demo →