vulns.co
/
GKData.io MCP

Back to Reports

A private page was stored at a static-looking URL

This is cache deception, not poisoning. The proof is two clients: one authenticated request that stores the private body, and one request with no credentials that receives it. Do not leave someone else's data in the cache.

Editorial decision card. This page links to a source-verified public disclosure and contains only original defensive analysis. It does not mirror upstream HTML, payloads, attachments, private submissions, or exploit steps.
Original severity
Medium (5.0) source-reported; not rescored by vulns.co
Public source
hackerone disclosure
Program / vendor
Algolia
Product / surface
algolia.com cache
Weakness
Web cache deception
Affected boundary
An authenticated response and a later unauthenticated cache read
Disclosure date
2023-04-19
Public status checked
2026-09-28
Public attribution
golim

What the evidence established

Algolia's summary says the cache stored a private authenticated response at a URL that looked like a static file. Someone who later requested that URL could read the cached body. The program resolved it.

Why the impact was credible

The source reported disclosure of personal information that had been cached from an authenticated session.

Durable engineering lesson

This is cache deception, not poisoning. The proof is two clients: one authenticated request that stores the private body, and one request with no credentials that receives it. Do not leave someone else's data in the cache.

Control pattern

Do not cache an authenticated response on a path the cache treats as static. Vary on the viewer, or refuse to store that response.

Primary public disclosure

Read the original source ↗

Upstream availability and wording can change. Public status was last checked 2026-09-28.