CWE-524Base

Use of Cache Containing Sensitive Information

Incomplete in the CWE catalog · 58 CVEs mapped

58
CVEs mapped
5.9
Median CVSS
What it is

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Recent examples
6.5cvss
CVE-2026-84933

CVE-2026-84933 - MEDIUM Severity Vulnerability

undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.

MEDIUMno explanation yet
0%
epss
5.7cvss
CVE-2026-15743

CVE-2026-15743 - MEDIUM Severity Vulnerability

Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared cache, and may be reused in responses to requests from other users. (This includes requests with an Authorization header.) Configuring the expires time to "0" to disable caching, as documented, is ignored.

MEDIUMno explanation yet
0%
epss
4.8cvss
CVE-2026-54625

CVE-2026-54625 - MEDIUM Severity Vulnerability

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site, language, path, and timezone but not the declared header values. Although set_page_cache adds those names to the response Vary header, get_page_cache retrieves the first stored variant under the same header-agnostic key. When CMS_PAGE_CACHE is enabled and a plugin varies content on a header such as Country-Code, one visitor can receive another visitor’s request-specific content, and an unauthenticated attacker can prime the cache with attacker-chosen content. This issue is fixed in versions 5.0.8 and 5.1.0.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-524
Abstraction
Base
Structure
Simple
Status
Incomplete