Package
homepage
Component
http-cache-semantics
Latest update
7.5
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This advisory record is disputed upstream.
The maintainer of http-cache-semantics has closed the report: this isn't a vulnerability, because RFC 9111 Section 7.3 explicitly permits a shared cache to store and reuse a response carrying a Set-Cookie header field: "Note that the Set-Cookie response header field does not inhibit caching; a cacheable response with a Set-Cookie header field can be (and often is) used to satisfy subsequent requests to caches." Preventing cross-user reuse is the role of Cache-Control: private, not of response freshness directives such as max-stale.
No upstream code change is expected. A withdrawal request against the advisory record is tracked at https://github.com/github/advisory-database/issues/10139.
Status
Impact
Waiting on upstream to publish a fixed version for this vulnerability.
Status