pingora-cache is vulnerable to Cache Poisoning
84
High Risk
Affected versions of this package are vulnerable to cache poisoning. The default cache key implementation generates cache keys using only the URI path and does not include other important request attributes such as the Host header. This allows an attacker to poison shared cache entries and cause cross-origin responses to be served to users. In multi-tenant deployments, this may lead to cross-tenant data leakage or the delivery of malicious content to legitimate users. The issue is addressed by removing the insecure default cache key implementation and requiring users to explicitly define their own cache key logic.
You are affected if you are using a version that falls within the vulnerable range.
pingora-cache is vulnerable to Cache Poisoning in versions 0.1.0 - 0.7.0.
Upgrade the pingora-cache library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant