VulnSea

CWE-1275

CVEs classified under CWE-1275, newest first.

8 CVEsRSS

CVE-2026-61687High· 7.1
yesterday

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

Twilighthatchet-dev · hatchetvia NVD
CVE-2026-69215Medium· 6.8
1w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie.…

Sunlithttp4s · org.http4s:http4s-client_2.12EPSS 0.43%via NVD
CVE-2026-53660High· 7.4
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and O…

TwilightOpenIdentityPlatform · OpenAMEPSS 0.33%via NVD
CVE-2026-81888Medium· 5.4
3w ago

@hono/oauth-providers is Authentication middleware for Hono

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…

Sunlithono · @hono/oauth-providersEPSS 0.15%via NVD
CVE-2026-47889High· 7.5
3w ago

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Twilightvmware · spring_frameworkEPSS 0.25%via NVD
CVE-2026-73847Medium· 6.8PoC
1mo ago

Emlog is an open source website building system

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an att…

TwilightEPSS 0.20%via NVD
CVE-2026-55688Medium· 4.0
2mo ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stor…

SunlitEPSS 0.33%via NVD
CVE-2026-1697Medium· 6.5
6mo ago

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

Sunlitarcinfo · pcvueEPSS 0.12%via NVD
CWE-1275 vulnerabilities (CVEs) · VulnSea