This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Matteo Collina
nodeland.dev
did:plc:2q7mnid6di5sxgzzpsdvdu47
🟡 Moderate: Shared-cache disclosure (CVE-2026-9678).
The cache interceptor mishandled whitespace-padded Cache-Control like `private=" authorization"`, so authenticated responses could be cached & served to other users in shared mode.
v7/v8. Fixed in 7.28.0 / 8.5.0.
2026-06-18T15:59:01.471Z