<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cache-Poisoning — PoC Archive</title><link>https://poc.intelseclab.com/tags/cache-poisoning/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cache-poisoning/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7. Status: Patched (9.2.15 / 10.1.4). Affects: Apache Traffic Server. Tags: apache, traffic-server, ats, header-injection, metadata-spoof, cache-poisoning, acl-bypass, plugin, CVE-2026-33267.</description><category>web</category><category>Critical</category><category>apache</category><category>traffic-server</category><category>ats</category><category>header-injection</category><category>metadata-spoof</category><category>cache-poisoning</category><category>acl-bypass</category><category>plugin</category><category>CVE-2026-33267</category></item><item><title>ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-55315-kestrel-http-request-smuggling/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-55315-kestrel-http-request-smuggling/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2025-55315. Status: Weaponized. Affects: ASP.NET Core Kestrel web server (Microsoft.AspNetCore.Server.Kestrel). Tags: aspnet-core, kestrel, http-request-smuggling, chunked-transfer-encoding, dotnet, python, cwe-444, ssrf, cache-poisoning, webshell-upload.</description><category>network</category><category>Critical</category><category>aspnet-core</category><category>kestrel</category><category>http-request-smuggling</category><category>chunked-transfer-encoding</category><category>dotnet</category><category>python</category><category>cwe-444</category><category>ssrf</category><category>cache-poisoning</category><category>webshell-upload</category></item><item><title>dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-4893-dnsmasq-ecs-spoofing/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-4893-dnsmasq-ecs-spoofing/</guid><description>Medium severity — network · CVE-2026-4893. Status: PoC. Affects: dnsmasq (DNS forwarder/cache). Tags: dnsmasq, dns, edns, ecs, rfc7871, cache-poisoning, spoofing, udp.</description><category>network</category><category>Medium</category><category>dnsmasq</category><category>dns</category><category>edns</category><category>ecs</category><category>rfc7871</category><category>cache-poisoning</category><category>spoofing</category><category>udp</category></item><item><title>nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_nghttpx-http-upgrade-queue-poisoning/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_nghttpx-http-upgrade-queue-poisoning/</guid><description>High severity — network · None assigned as of 2026-07-03. Status: PoC. Affects: nghttp2's nghttpx reverse proxy. Tags: nghttp2, nghttpx, reverse-proxy, request-smuggling, response-queue-poisoning, http-desync, upgrade-request, cache-poisoning.</description><category>network</category><category>High</category><category>nghttp2</category><category>nghttpx</category><category>reverse-proxy</category><category>request-smuggling</category><category>response-queue-poisoning</category><category>http-desync</category><category>upgrade-request</category><category>cache-poisoning</category></item><item><title>Next.js unstable_cache Object-Argument Cache-Key Collision</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_nextjs-unstable-cache-key-collision/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_nextjs-unstable-cache-key-collision/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: Next.js (App Router, Data Cache). Tags: nextjs, unstable_cache, cache-poisoning, cache-key-collision, data-cache, information-disclosure, server-side-caching, javascript.</description><category>web</category><category>High</category><category>nextjs</category><category>unstable_cache</category><category>cache-poisoning</category><category>cache-key-collision</category><category>data-cache</category><category>information-disclosure</category><category>server-side-caching</category><category>javascript</category></item><item><title>Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-x-nextjs-data-cache-poisoning/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-x-nextjs-data-cache-poisoning/</guid><description>Low severity (CVSS 3.1) — web · CVE-2026-44572. Status: Researched. Affects: Next.js Pages Router (redirect handling via middleware or next.config.js). Tags: cache-poisoning, x-nextjs-data, redirect, CDN, header-smuggling, Next.js, Pages-Router, unauthenticated.</description><category>web</category><category>Low</category><category>cache-poisoning</category><category>x-nextjs-data</category><category>redirect</category><category>CDN</category><category>header-smuggling</category><category>Next.js</category><category>Pages-Router</category><category>unauthenticated</category></item><item><title>Next.js RSC Response Cache Poisoning (CVE-2026-44576)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-response-cache-poisoning/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-response-cache-poisoning/</guid><description>Medium severity (CVSS 5.4) — web · CVE-2026-44576. Status: Weaponized. Affects: Next.js App Router deployments using React Server Components (RSC) behind shared caches. Tags: cache-poisoning, RSC, response-confusion, Next.js, shared-cache, unauthenticated.</description><category>web</category><category>Medium</category><category>cache-poisoning</category><category>RSC</category><category>response-confusion</category><category>Next.js</category><category>shared-cache</category><category>unauthenticated</category></item><item><title>Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-cache-busting-weak-hash-collision/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-cache-busting-weak-hash-collision/</guid><description>Low severity (CVSS 3.7) — web · CVE-2026-44582. Status: Weaponized. Affects: Next.js App Router. Tags: cache-poisoning, RSC, weak-hash, Next.js, unauthenticated.</description><category>web</category><category>Low</category><category>cache-poisoning</category><category>RSC</category><category>weak-hash</category><category>Next.js</category><category>unauthenticated</category></item><item><title>Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-csp-nonce-cache-poisoned-xss/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-csp-nonce-cache-poisoned-xss/</guid><description>Medium severity (CVSS 4.7) — web · CVE-2026-44581. Status: Weaponized. Affects: Next.js App Router applications using CSP nonces. Tags: XSS, cache-poisoning, CSP-nonce, Next.js, App-Router, unauthenticated.</description><category>web</category><category>Medium</category><category>XSS</category><category>cache-poisoning</category><category>CSP-nonce</category><category>Next.js</category><category>App-Router</category><category>unauthenticated</category></item></channel></rss>