{"id":"GHSA-9pq4-5hcf-288c","summary":"Cache poisoning in @sveltejs/adapter-vercel","details":"Versions of `@sveltejs/adapter-vercel` prior to 6.3.2 are vulnerable to cache poisoning. An internal query parameter intended for Incremental Static Regeneration (ISR) is accessible on all routes, allowing an attacker to cause sensitive user-specific responses to be cached and served to other users.\n\nSuccessful exploitation requires a victim to visit an attacker-controlled link while authenticated.\n\nExisting deployments are protected by Vercel's WAF, but users should upgrade as soon as possible.","aliases":["CVE-2026-27118"],"modified":"2026-02-23T23:43:51.037809Z","published":"2026-02-19T15:18:02Z","database_specific":{"cwe_ids":["CWE-346"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-19T15:18:02Z","nvd_published_at":"2026-02-20T22:16:29Z"},"references":[{"type":"WEB","url":"https://github.com/sveltejs/kit/security/advisories/GHSA-9pq4-5hcf-288c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27118"},{"type":"PACKAGE","url":"https://github.com/sveltejs/kit"}],"affected":[{"package":{"name":"@sveltejs/adapter-vercel","ecosystem":"npm","purl":"pkg:npm/%40sveltejs/adapter-vercel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-9pq4-5hcf-288c/GHSA-9pq4-5hcf-288c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}