Re: no-vary: security - cache poisoning

Am 18.01.2026 um 18:39 schrieb David Benjamin:
> Wouldn't such an intermediary also be able to poison a cache by sending 
> other caching headers wrong or the wrong content? I think that's just 
> generally part of the threat model for caches and intermediaries, unless 
> I'm missing something here

Probably.

What's new (?) is that the cache can cause clients to store responses 
under the incorrect key. Does that make a difference? Dunno.

Best regards, Julian

Received on Sunday, 18 January 2026 19:42:56 UTC