CVE-2026-85085Critical· 9.6▾ MidnightThe Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85125Medium· 5.4The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation
CVE-2026-73419Medium· 6.8NextAuth.js provides authentication for Next.js
CVE-2026-89178High· 8.8WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability
GHSA-x445-f3h2-j279Medium· 6.8Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
CVE-2026-44894High· 7.5Netty's Default QUIC token handler accepts any client-supplied token
CVE-2026-48022Medium· 6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects