vulns.co
/
GKData.io MCP
IF / Infrastructure

Cache deception and cache poisoning

Review cache keys, response eligibility, and invalidation so a response remains correct for the requester and representation that produced it.

Guide 07 / 154 review notesUpdated 2026-10-11

The review

What to look for

Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.

  1. Classify response data

    Separate public, tenant-scoped, user-scoped, and diagnostic responses before deciding what may be stored.

  2. Trace the key

    Document every request property that changes representation, permission, locale, or tenant and confirm it participates in cache selection.

  3. Review invalidation

    Check privilege changes, logout, mutations, and deployment events for a safe freshness or purge strategy.

  4. Bound capacity

    Ensure key cardinality and cache partitioning preserve availability without collapsing distinct security contexts.

What to produce

  • Cache eligibility matrix
  • Key and variation inventory
  • Invalidation policy

Common mistakes

  • Caching personalized representations as public
  • Forgetting authorization-affecting variation
  • Assuming freshness implies authorization

Continue the study

Reading & source context

Editorial notes above connect these references. Open each record for its original source and review date.

Visual models

Connected disclosures

From the field toolkit

Guide by GK Data · Research snapshot 2026-10-04.
Sources and review dates are preserved in the library provenance.

Next skillAgents, MCP, and retrieval →