VulnSea

CWE-1289

CVEs classified under CWE-1289, newest first.

16 CVEsRSS

CVE-2026-86831High· 8.7
5d ago

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namesp…

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namesp…

TwilightAWS · aws-network-policy-agentEPSS 0.46%via NVD
CVE-2026-88255Medium· 6.3
5d ago

Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the pre-broadcast dedup …

Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Tempo duplicate-submission gate twice with one signed transaction. MPP.Methods.Tempo reserves the pre-broadcast dedup …

SunlitZenHive · mppEPSS 0.39%via NVD
CVE-2026-89049Critical· 9.9
1w ago

Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms …

MidnightAWS · Amazon SSM AgentEPSS 0.36%via CVEORG
CVE-2026-76977Medium· 4.3
1w ago

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authenticated victim visits the attacker's p…

SunlitSAP_SE · SAPUI5(Frame Options Allowlist)EPSS 0.22%via NVD
CVE-2026-84428High· 7.5
2w ago

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and th…

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and th…

Twilightfastify · fastifyEPSS 0.30%via NVD
CVE-2026-74994Medium· 6.0
2w ago

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace

The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user ad…

SunlitErlang · otpEPSS 0.36%via NVD
CVE-2026-18446High· 7.5
1mo ago

fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authority (CVE-2026-18446)

A flaw was found in fast-uri. This vulnerability arises because fast-uri incorrectly parses Uniform Resource Identifiers (URIs) when a backslash is used in place of a forward slash to introduce the authority component. This discrepancy wit…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.22%via CSAF
CVE-2026-47729Medium· 6.5PoC
2mo ago

Squid is a caching proxy for the Web

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date i…

Twilightsquid-cache · squidEPSS 1.5%via NVD
GHSA-6c87-g9pw-78fxLow· 3.7
2mo ago

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

Contrast's Imagepuller registryFor uses unanchored suffix matching, leaking auth credentials and trusted CA configuration to sibling-domain registries

Sunlitedgelesssys · github.com/edgelesssys/contrastvia GHSA
CVE-2026-48710Medium· 6.5CISA KEVPoC
3mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

Midnightstarlette · starletteEPSS 36%via NVD
CVE-2026-39821Critical· 9.6
4mo ago

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior …

Midnightgolang · netEPSS 0.69%via NVD
CVE-2026-39826Medium· 5.4
4mo ago

html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826)

A flaw was found in html/template. A trusted template author could craft a script tag with an empty or whitespace-only 'type' attribute. This vulnerability causes the template engine to incorrectly escape data passed into the script block,…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.37%via CSAF
CVE-2025-62718Critical· 9.9PoC⚖ disputed
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a tra…

Abyssalaxios · axiosEPSS 1.2%via NVD
CVE-2026-33810High· 8.2
5mo ago

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted ce…

Twilightgolang · goEPSS 0.34%via NVD
CVE-2026-22569Medium· 5.4
5mo ago

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

Sunlitzscaler · client_connectorEPSS 0.18%via NVD
CVE-2026-27610Medium· 5.3
6mo ago

Parse Dashboard is a standalone dashboard for managing Parse Server apps

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses the same cache key for both master key and read-only master key when resolving function…

SunlitEPSS 0.34%via NVD
CWE-1289 vulnerabilities (CVEs) · VulnSea