Fetching from the wire…
Infra2026-08-06 · source-backed
arXiv 2608.04744 points out that operators routinely include HTTP request fields in cache keys that don't affect the response, letting a client fetch the same object under many different keys. Sustained generation of redundant entries degrades cache effectiveness and pushes load back to origin, enabling eviction-dependent attacks and potentially DoS. Reproduced across five stand-alone caching proxies, with a characterization of how key parameters trade attacker cost against hit rate. Cache-key design is a security decision, not a performance-tuning detail.
Each link below shares sources, entities, or timing with this story.
Shared entity: HTTP / Same source domain / Shared topic / Earlier coverage / Tension
Both cover HTTP; reported by the same outlet (arxiv.org); overlapping topics (against, attack).
Shared entity: Cache / Same source domain / Shared topic / Earlier coverage
Both cover Cache; reported by the same outlet (arxiv.org); overlapping topics (cache, caching, cost).
Both cover Cache; reported by the same outlet (arxiv.org); overlapping topics (caching, cost).
Shared entity: HTTP / Same source domain / Earlier coverage / Tension
Both cover HTTP; reported by the same outlet (arxiv.org); earlier HTTP coverage from 2026-07-14.
Shared entity: Cache / Shared topic / Earlier coverage / Tension
Both cover Cache; overlapping topics (cache, cost); earlier Cache coverage from 2026-03-16.
Shared entity: HTTP / Shared topic / Earlier coverage
Both cover HTTP; overlapping topics (against, attack, keys); earlier HTTP coverage from 2026-07-25.
Shared entity: Cache / Shared topic / Earlier coverage
Both cover Cache; overlapping topics (cache, caching, cost); earlier Cache coverage from 2026-03-16.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (attack, attacker, cost); pushes against this story (but).