CWE-290
CVEs classified under CWE-290, newest first.
131 CVEsRSS
CVE-2026-19538High· 7.5The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
CVE-2026-49757CriticalPoCAshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
CVE-2026-76835Critical· 9.1OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/r…
CVE-2026-77337NoneCakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications
CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CP…
CVE-2026-75509Medium· 6.5joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing…
CVE-2026-69183High· 7.5Monkeytype is a minimalistic and customizable typing test
Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before t…
CVE-2026-71485Critical· 9.1Centrifugo is an open-source scalable real-time messaging server
Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…
CVE-2026-72816Medium· 6.5go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…
CVE-2026-72815Medium· 6.5PoCgo-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access…
CVE-2026-0292Medium· 6.0⚖ disputedAn authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…
CVE-2026-19291High· 8.8Bluetooth re-pairing with an existing device can use a lower security level
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
CVE-2026-16101High· 8.8Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
CVE-2026-73840Medium· 5.3OpenChoreo is a complete, open-source developer platform for Kubernetes
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provi…
CVE-2026-72809High· 8.0SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…
SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…
CVE-2026-18639High· 7.3When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim a…
CVE-2026-18972Critical· 9.6An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\"
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…
CVE-2026-54763HighTraefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
CVE-2026-48063CriticalBaileys is a cocket-based TS/JavaScript API for WhatsApp Web
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…
CVE-2026-59224High· 8.0Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVE-2026-16076Medium· 6.3A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5
A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username …
CVE-2026-50141HighWoodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation
CVE-2026-61428High· 7.3PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhoo…
CVE-2026-55641High· 8.29Router is an AI router & token saver
9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypas…
CVE-2026-54089Critical· 9.1File Browser: Authentication Bypass via Proxy Auth Header Forgery
File Browser: Authentication Bypass via Proxy Auth Header Forgery
CVE-2026-55501High· 7.39router: Login brute-force protection bypass via spoofed X-Forwarded-For header
9router: Login brute-force protection bypass via spoofed X-Forwarded-For header
CVE-2026-49353High· 7.59router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
OpenClaw: Slack allowFrom could bind to mutable display names
CVE-2026-53811High· 8.8OpenClaw: Matrix allowFrom could bind to mutable display names
OpenClaw: Matrix allowFrom could bind to mutable display names
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers