VulnSea

CWE-290

CVEs classified under CWE-290, newest first.

131 CVEsRSS

CVE-2026-19538High· 7.5
1mo ago

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

▾ Twilightnlnetlabs · nsdEPSS 0.23%via NVD
CVE-2026-49757CriticalPoC
1mo ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

▾ Abyssalash_authentication · ash_authenticationEPSS 0.68%via GHSA
CVE-2026-76835Critical· 9.1
1mo ago

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/r…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-77337None
1mo ago

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and from 4.0.0 through 4.2.0 allow authentication bypass and potential CP…

▾ SunlitEPSS 0.70%via NVD
CVE-2026-75509Medium· 6.5
1mo ago

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing…

▾ SunlitEPSS 0.12%via NVD
CVE-2026-69183High· 7.5
1mo ago

Monkeytype is a minimalistic and customizable typing test

Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before t…

▾ TwilightEPSS 0.48%via NVD
CVE-2026-71485Critical· 9.1
1mo ago

Centrifugo is an open-source scalable real-time messaging server

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers,…

▾ Midnightcentrifugal · github.com/centrifugal/centrifugoEPSS 0.61%via NVD
CVE-2026-72816Medium· 6.5
1mo ago

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.30%via NVD
CVE-2026-72815Medium· 6.5PoC
1mo ago

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access…

▾ Twilightgo-chi · github.com/go-chi/chi/v5/middlewareEPSS 0.50%via NVD
CVE-2026-0292Medium· 6.0⚖ disputed
1mo ago

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…

An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary…

▾ Sunlitpaloaltonetworks · prisma_access_agentEPSS 0.13%via NVD
CVE-2026-19291High· 8.8
1mo ago

Bluetooth re-pairing with an existing device can use a lower security level

Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.

▾ TwilightEPSS 0.35%via NVD
CVE-2026-16101High· 8.8
1mo ago

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device

Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

▾ TwilightEPSS 0.35%via NVD
CVE-2026-73840Medium· 5.3
1mo ago

OpenChoreo is a complete, open-source developer platform for Kubernetes

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provi…

▾ Sunlitopenchoreo · github.com/openchoreo/openchoreoEPSS 0.35%via NVD
CVE-2026-72809High· 8.0
1mo ago

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.30%via NVD
CVE-2026-18639High· 7.3
1mo ago

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username

When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim a…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-18972Critical· 9.6
1mo ago

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\"

An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

▾ MidnightEPSS 0.35%via NVD
CVE-2026-64665High· 8.1
1mo ago

Statamic is a Laravel and Git powered content management system (CMS)

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that does not guarantee verified email addresses, an unauthenticated attacker could sign in a…

▾ Twilightstatamic · statamic/cmsEPSS 0.54%via NVD
CVE-2026-54763High
1mo ago

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

▾ Twilighttraefik · github.com/traefik/traefik/v2EPSS 0.24%via GHSA
CVE-2026-48063Critical
1mo ago

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…

▾ Midnightbaileys · baileysEPSS 0.22%via NVD
CVE-2026-59224High· 8.0
2mo ago

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

▾ Twilightopen-webui · open-webuiEPSS 0.39%via GHSA
CVE-2026-16076Medium· 6.3
2mo ago

A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5

A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_send of the file astrbot/dashboard/routes/open_api.py of the component API. Such manipulation of the argument Username …

▾ SunlitEPSS 0.51%via NVD
CVE-2026-50141High
2mo ago

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation

▾ Twilightwoodpecker · go.woodpecker-ci.org/woodpecker/v3EPSS 0.43%via GHSA
CVE-2026-61428High· 7.3
2mo ago

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhoo…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-55641High· 8.2
2mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypas…

▾ TwilightEPSS 0.32%via NVD
CVE-2026-54089Critical· 9.1
2mo ago

File Browser: Authentication Bypass via Proxy Auth Header Forgery

File Browser: Authentication Bypass via Proxy Auth Header Forgery

▾ Midnightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.61%via GHSA
CVE-2026-55501High· 7.3
2mo ago

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

9router: Login brute-force protection bypass via spoofed X-Forwarded-For header

▾ Twilight9router · 9routerEPSS 0.52%via GHSA
CVE-2026-49353High· 7.5
2mo ago

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING

▾ Twilight9router · 9routerEPSS 0.36%via GHSA
GHSA-c29c-2q9c-pc86High
2mo ago

OpenClaw: Slack allowFrom could bind to mutable display names

OpenClaw: Slack allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-53811High· 8.8
2mo ago

OpenClaw: Matrix allowFrom could bind to mutable display names

OpenClaw: Matrix allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
GHSA-rggc-m335-3wvjHigh
2mo ago

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

▾ Twilightopenclaw · openclawvia GHSA
CWE-290 vulnerabilities (CVEs) — page 3 · VulnSea