CVE-2025-59163None▾ Sunlitvet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP Host and Origin header validation. Data from the vet scan sqlite3 database may be exposed t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP Host and Origin header validation. Data from the vet scan sqlite3 database may be exposed to remote attackers when vet is used as an MCP server in SSE mode with default ports through the sqlite3 query MCP tool. This issue is fixed in version 1.12.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2018-7160High· 8.8The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution
CVE-2026-107292Medium· 6.4Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2025-8036High· 8.1Thunderbird cached CORS preflight responses across IP address changes
CVE-2026-97875High· 8.1Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding
CVE-2026-61743Medium· 6.3Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts
CVE-2026-75514Medium· 5.9BunkerWeb is an open-source, next-generation Web Application Firewall