#1148405 node-got: CVE-2026-93748

Package:
src:node-got
Source:
src:node-got
Submitter:
Salvatore Bonaccorso
Date:
2026-09-19 14:25:01 UTC
Severity:
normal
Tags:
#1148405#5
Date:
2026-09-19 14:23:22 UTC
From:
To:
Hi,

The following vulnerability was published for node-got.

AFAICS, node-got provides the problematic node-http-cache-semantics.
No upstream fix exists yet at time of writing.

CVE-2026-93748[0]:
| http-cache-semantics through 4.2.0 fails to properly validate
| security-zeroed cache entries when processing client max-stale
| directives, allowing unauthenticated attackers to retrieve cached
| responses belonging to other users. Attackers can request the same
| URL with a large max-stale value to obtain another user's Set-Cookie
| session credentials from shared-cache entries that were deliberately
| zeroed for security reasons.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93748
https://www.cve.org/CVERecord?id=CVE-2026-93748
[1] https://github.com/kornelski/http-cache-semantics/issues/56

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore