CVE-2026-48063Critical▾ MidnightBaileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or "on-demand" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
baileys < 6.7.22@whiskeysockets/baileys < 6.7.22baileys >= 7.0.0-rc.1, < 7.0.0-rc12@whiskeysockets/baileys >= 7.0.0-rc.1, < 7.0.0-rc12Patched in:
baileys 6.7.22@whiskeysockets/baileys 6.7.22baileys 7.0.0-rc12@whiskeysockets/baileys 7.0.0-rc12Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86039High· 8.2libp2p is a JavaScript implementation of the libp2p networking stack
CVE-2026-77119Medium· 5.9A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…
CVE-2026-19941Medium· 5.9An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…
CVE-2026-88819Medium· 6.3In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
CVE-2026-75509Medium· 6.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards
CVE-2026-73840Medium· 5.3OpenChoreo is a complete, open-source developer platform for Kubernetes