Sensitive Information Exposure in ZenHive mpp for Elixir Applications
CVE-2026-89186
What is CVE-2026-89186?
The ZenHive mpp library for Elixir is vulnerable to sensitive information exposure due to the improper handling of HTTP cache responses. In specific versions, the library allows a shared HTTP cache to mistakenly store a response meant only for clients who have completed payment, enabling unauthorized access to this content. The issue arises when the application's cache-control headers can override the private cache-control settings that are supposed to protect sensitive information, allowing unauthorized users to access paid content. This vulnerability can lead to significant data leakage if not addressed, as it enables unintended dissemination of sensitive information.
Affected Version(s)
mpp 0.1.0 < 0.16.2
mpp 2d4d1d94aae7790ae0623063961adbeef171fa71 < 2fd91a5ecbd0b0ad2a4ac202b79659e8126dbc0b
