CWE-524: CWE-524
Yearly Trend
Top Affected Vendors
All CWE-524 CVEs (13)
The AuthKit library for Next.js versions 2.11.0 and below fails to apply anti-caching headers to authenticated responses. This allows session tokens t...
Nov 21, 2025This vulnerability in Shopware allows session fixation attacks where cached 404 pages inadvertently expose session cookies to subsequent users. Attack...
Mar 6, 2024Mastodon servers with AUTHORIZED_FETCH enabled are vulnerable to web cache poisoning where ActivityPub endpoints for pinned posts and featured hashtag...
Feb 4, 2026Axios Cache Interceptor versions before 1.11.1 incorrectly cache responses without considering Authorization headers, allowing cached responses from o...
Dec 29, 2025Next.js Image Optimization API routes have a cache key confusion vulnerability that could serve cached image responses to unauthorized users. This aff...
Aug 29, 2025A vulnerability in libsoup's SoupCache ignores the HTTP Vary header when evaluating cached responses, allowing cached content to be incorrectly reused...
Sep 3, 2025Chamilo LMS 1.11.2 fails to properly clear cached sensitive user data from the Social Network/personal_data endpoint after logout. This allows subsequ...
Jan 16, 2026Hono web framework versions before 4.11.7 have a cache middleware vulnerability that improperly handles HTTP cache control directives. This allows pri...
Jan 27, 2026The CVE-2024-49580 vulnerability in JetBrains Ktor's HttpCache Plugin involves improper caching that could allow unauthorized disclosure of cached HTT...
Oct 17, 2024SINEC Traffic Analyzer versions before V2.0 have a vulnerability where the web service doesn't properly handle cacheable HTTP responses. This allows a...
Aug 13, 2024Flask versions 3.1.2 and below have a cache vulnerability where accessing session keys with certain Python operators (like 'in') fails to set proper c...
Feb 21, 2026The Brother iPrint&Scan Android app versions 6.13.7 and earlier improperly stores application files in an external cache directory accessible to other...
Dec 9, 2025This vulnerability allows an attacker with physical access to a Mac to view deleted notes due to improper cache handling. It affects macOS users runni...
Dec 12, 2025About CWE-524 (CWE-524)
Our database tracks 13 CVEs classified as CWE-524, with 1 rated critical and 1 rated high severity. The average CVSS score for CWE-524 vulnerabilities is 5.6.
External reference: View CWE-524 on MITRE CWE →
Monitor CWE-524 Vulnerabilities
Get alerted when new CWE-524 CVEs affect your infrastructure.
Start Monitoring Free