{
  "slug": "cache",
  "name": "Cache deception and cache poisoning",
  "category": "Infrastructure",
  "summary": "Review cache keys, response eligibility, and invalidation so a response remains correct for the requester and representation that produced it.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Cache configuration",
    "Response headers and variation rules",
    "Authorization and tenant model"
  ],
  "review": [
    {
      "title": "Classify response data",
      "body": "Separate public, tenant-scoped, user-scoped, and diagnostic responses before deciding what may be stored."
    },
    {
      "title": "Trace the key",
      "body": "Document every request property that changes representation, permission, locale, or tenant and confirm it participates in cache selection."
    },
    {
      "title": "Review invalidation",
      "body": "Check privilege changes, logout, mutations, and deployment events for a safe freshness or purge strategy."
    },
    {
      "title": "Bound capacity",
      "body": "Ensure key cardinality and cache partitioning preserve availability without collapsing distinct security contexts."
    }
  ],
  "outputs": [
    "Cache eligibility matrix",
    "Key and variation inventory",
    "Invalidation policy"
  ],
  "pitfalls": [
    "Caching personalized representations as public",
    "Forgetting authorization-affecting variation",
    "Assuming freshness implies authorization"
  ],
  "references": {
    "resources": [
      {
        "id": "arxiv-2026-cache-key-precision-and-capacity",
        "title": "Web cache key precision and capacity isolation",
        "url": "https://vulns.co/research/resources/arxiv-2026-cache-key-precision-and-capacity/"
      },
      {
        "id": "nuxt-2026-rendered-payload-cache-authorization",
        "title": "Nuxt: rendered-data caches must preserve request authorization",
        "url": "https://vulns.co/research/resources/nuxt-2026-rendered-payload-cache-authorization/"
      },
      {
        "id": "nextjs-2026-response-metadata-representation-boundary",
        "title": "Next.js: response metadata must preserve representation boundaries",
        "url": "https://vulns.co/research/resources/nextjs-2026-response-metadata-representation-boundary/"
      }
    ],
    "diagrams": [
      {
        "id": "combined-view-source-authorization",
        "title": "Combined views preserve every source's access boundary",
        "url": "https://vulns.co/research/diagrams/combined-view-source-authorization/"
      }
    ],
    "reports": [
      {
        "id": "github-cross-repository-comparison-authorization-2025",
        "title": "GitHub comparison output lacked source-repository authorization",
        "url": "https://vulns.co/research/reports/github-cross-repository-comparison-authorization-2025/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/cache/",
  "markdown_url": "https://vulns.co/skills/cache/SKILL.md"
}
