CVE Explorer
CVE-2026-39972
Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior to 0.22.0, a cache key collision vulnerability in TopicSelectorStore allows an attacker to poison the match result cache, potentially causing private updates to be delivered to unauthorized subscribers or blocking delivery to authorized ones. The cache key was constructed by concatenating the topic selector and topic with an underscore separator. Because both topic selectors an
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"mercure","vendor":"dunglas","versions":[{"status":"affected","version":"< 0.22.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:227b5ad262147169f2c8f3a374d157150486279eb3b5f0d71a6ce8014e24542d · sha256:46cf3faa6aa178f2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:227b5ad262147169f2c8f3a374d157150486279eb3b5f0d71a6ce8014e24542d · sha256:46cf3faa6aa178f2… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1289","description":"CWE-1289: Improper Validation of Unsafe Equivalence in Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:227b5ad262147169f2c8f3a374d157150486279eb3b5f0d71a6ce8014e24542d · sha256:46cf3faa6aa178f2… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/dunglas/mercure/commit/4964a69be904fd61e35b5f1e691271663b6fdd64","tags":["x_refsource_MISC"],"url":"https://github.com/dunglas/mercure/commit/4964a69be904fd61e35b5f1e691271663b6fdd64"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:227b5ad262147169f2c8f3a374d157150486279eb3b5f0d71a6ce8014e24542d · sha256:46cf3faa6aa178f2… · /containers/cna/references/1
{"name":"https://github.com/dunglas/mercure/security/advisories/GHSA-hwr4-mq23-wcv5","tags":["x_refsource_CONFIRM"],"url":"https://github.com/dunglas/mercure/security/advisories/GHSA-hwr4-mq23-wcv5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:227b5ad262147169f2c8f3a374d157150486279eb3b5f0d71a6ce8014e24542d · sha256:46cf3faa6aa178f2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.