Threats Tagged 'cwe-524'
View all threats tagged with 'cwe-524'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-524'
Click on any threat for detailed analysis and mitigation recommendations
0 A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same process, the module-level token cache fails to key its cached tokens by the requested audience. Consequently, a valid, unexpired token minted for a sensitive service (Service A) can be retrieved from the cache and sent to a secondary service (Service B). An attacker who operates, compromises, or monitors traffic to Service B can capture this token and replay it to impersonate the victim application against Service A. Join the discussion | CVE Database V5 | 09/22/2026, 21:48:26 UTC Added: 09/22/2026, 22:03:27 UTC |
Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the connection before the wrapped application runs, and registers no register_before_send/2 callback. Plug.Conn.put_resp_header/3 replaces an existing header, so a mounting application that sets its own cache-control on the paid resource (for example public, max-age=3600) silently overrides the private the library relies on, and a CDN or reverse proxy can then store the paid 200 together with its Payment-Receipt and serve both to unpaid clients. The library-level guarantee is therefore defeatable by the application it protects. For the same reason a downstream non-2xx response still carried Payment-Receipt, issuing a receipt for a response that delivered no resource. This issue affects mpp: from 0.1.0 before 0.16.2. Join the discussion | CVE Database V5 | 09/16/2026, 08:24:15 UTC Added: 09/16/2026, 08:32:02 UTC |
0 CVE-2026-82755 is a vulnerability in ash-project's ash_authentication_oauth2_server where sensitive OAuth discovery metadata intended for one tenant can be cached and served to another tenant due to improper cache control headers. This occurs because tenant-specific metadata endpoints are sent with Cache-Control: public and no Vary header, causing shared HTTP caches to serve cached responses across tenants. This can lead to clients sending authorization codes and secrets to incorrect token endpoints and validating tokens against wrong keys. The issue affects versions from 0.1.3 up to but not including 0.3.1. Join the discussion | CVE Database V5 | 09/07/2026, 22:28:24 UTC Added: 09/07/2026, 22:37:55 UTC |
CVE-2026-15743 affects Catalyst::Plugin::Static::Simple for Perl versions up to 0.38. The plugin marks HTTP responses as publicly cacheable by always setting the Cache-Control header to "public" in the _serve_static method, ignoring configuration to disable caching. This behavior can cause sensitive information to be stored in shared caches and potentially served to unauthorized users, including those sending requests with Authorization headers. Join the discussion | CVE Database V5 | 08/20/2026, 18:15:26 UTC Added: 08/20/2026, 18:22:40 UTC |
0 CVE-2026-25703 is a high-severity vulnerability in SUSE NeuVector versions up to and including 5.4.9. It involves missing authentication for the critical /network/graph API in the manager component, which can lead to potential information leakage through cached sensitive data. Join the discussion | CVE Database V5 | 08/05/2026, 09:48:19 UTC Added: 08/05/2026, 10:12:00 UTC |
0 Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. Confidential data in the POST's response body would then leak to unauthorized requests. Though the request itself will not be deduped. This only applies to fetch calls with a request that has a different init than the one passed to fetch. A safe request would be: fetch(new Request(init), init). An unsafe request would be: fetch(new Request(init), aDifferentInit). This issue has been fixed in versions 15.5.21 and 16.2.11. Join the discussion | GCVE Database | 07/27/2026, 19:20:42 UTC Added: 07/23/2026, 01:18:05 UTC |
0 Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable. Join the discussion | CVE Database V5 | 07/23/2026, 09:14:11 UTC Added: 07/23/2026, 09:22:47 UTC |
0 Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors. Join the discussion | CVE Database V5 | 07/22/2026, 20:40:58 UTC Added: 07/22/2026, 21:08:29 UTC |
0 Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a Use of Cache Containing Sensitive Information vulnerability. The logic instructs caches not to cache the response, as it may contain information specific to a logged in user. This is handled in most cases, but some forms of access such as the Python in operator were overlooked. The severity and risk depend on the application being hosted behind a caching proxy that doesn't ignore responses with cookies, not setting a Cache-Control header to mark pages as private or non-cacheable, and accessing the session in a way that only touches keys without reading values or mutating the session. The issue has been fixed in version 3.1.3. Join the discussion | CVE Database V5 | 07/13/2026, 06:34:48 UTC Added: 02/21/2026, 05:47:12 UTC |
0 An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability. Join the discussion | CVE Database V5 | 07/09/2026, 19:03:44 UTC Added: 07/09/2026, 19:18:14 UTC |
Showing 1 to 10 of 27 results