Use of cache containing sensitive information in TerriaJS-Server - CVE-2026-77626
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose auth-gated upstream content.
The vulnerability exists due to improper cache-control configuration in the /proxy endpoint when a shared cache stores responses to proxied requests without varying by authorization. A remote attacker can request a proxied URL whose authenticated response has been cached to disclose auth-gated upstream content.
A shared cache or CDN in front of the server is required.