CWE-524
CWE-524 · 3 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-524, highest CVSS first.
- HIGH 7.3CVE-2026-25703public PoC
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information.
- UNSCOREDCVE-2026-19202public PoC
A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audiences within the same p…
- UNSCOREDCVE-2026-89186public PoC
Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serve it to clients that never paid. MPP.Plug.verify_credential in lib/mpp/plug.ex sets payment-receipt and cache-control: private on the conn…