A private page was stored at a static-looking URL
This is cache deception, not poisoning. The proof is two clients: one authenticated request that stores the private body, and one request with no credentials that receives it. Do not leave someone else's data in the cache.
- Original severity
- Medium (5.0) source-reported; not rescored by vulns.co
- Public source
- hackerone disclosure
- Program / vendor
- Algolia
- Product / surface
- algolia.com cache
- Weakness
- Web cache deception
- Affected boundary
- An authenticated response and a later unauthenticated cache read
- Disclosure date
- 2023-04-19
- Public status checked
- 2026-09-28
- Public attribution
- golim
What the evidence established
Algolia's summary says the cache stored a private authenticated response at a URL that looked like a static file. Someone who later requested that URL could read the cached body. The program resolved it.
Why the impact was credible
The source reported disclosure of personal information that had been cached from an authenticated session.
Durable engineering lesson
This is cache deception, not poisoning. The proof is two clients: one authenticated request that stores the private body, and one request with no credentials that receives it. Do not leave someone else's data in the cache.
Control pattern
Do not cache an authenticated response on a path the cache treats as static. Vary on the viewer, or refuse to store that response.
Primary public disclosure
Upstream availability and wording can change. Public status was last checked 2026-09-28.