Hi,
The following vulnerability was published for node-got.
AFAICS, node-got provides the problematic node-http-cache-semantics.
No upstream fix exists yet at time of writing.
CVE-2026-93748[0]:
| http-cache-semantics through 4.2.0 fails to properly validate
| security-zeroed cache entries when processing client max-stale
| directives, allowing unauthenticated attackers to retrieve cached
| responses belonging to other users. Attackers can request the same
| URL with a large max-stale value to obtain another user's Set-Cookie
| session credentials from shared-cache entries that were deliberately
| zeroed for security reasons.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-93748
https://www.cve.org/CVERecord?id=CVE-2026-93748
[1] https://github.com/kornelski/http-cache-semantics/issues/56
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore