axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
- Severity:
- Medium
Description
When a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization bypass.
Recommendation
Update the axios-cache-interceptor package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.11.1
- Patched version(s): 1.11.1
References
Related Issues
- webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence - CVE-2025-68157
- ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header - CVE-2026-55087
- FUXA has JWT Authentication Bypass via HTTP Referer header spoofing - CVE-2025-69985
- axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL - CVE-2025-27152
You might also like:
- Tags:
- npm
- axios-cache-interceptor
Anything's wrong? Let us know Last updated on January 05, 2026


