Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that resul
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extension
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extensio
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries
NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authenticatio
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with
In the Linux kernel, the following vulnerability has been resolved: drm/xe/uapi: Reject coh_none PAT index for CPU cach
Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.3.19, 4.4.13, 4.5.6, Mas
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A
Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29,
undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva
IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing an
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static
An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user i
Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Mid
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have
django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in
Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session
An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely,
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware
An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affe
Frequently Asked Questions
What is CWE-524?
CWE-524 (CWE-524) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-524?
There are 36 CVE records associated with CWE-524 in our database. Of these, 1 are critical severity, 11 are high severity, and 19 are medium severity.
How can I protect against CWE-524 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-524 using AI-powered security agents.
Detect CWE-524 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-524 vulnerabilities across your infrastructure.
Get Started