VulnSea

CWE-290

CVEs classified under CWE-290, newest first.

131 CVEsRSS

CVE-2026-53817High· 8.0
2mo ago

OpenClaw: Control UI locality spoofing could mint a durable admin device token

OpenClaw: Control UI locality spoofing could mint a durable admin device token

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-45045Medium· 5.3
2mo ago

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

GoFiber Vulnerable to X-Real-IP Spoofing via Header.Add() in BalancerForward

▾ Sunlitgofiber · github.com/gofiber/fiber/v3EPSS 0.46%via GHSA
CVE-2026-7656High· 8.1
3mo ago

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wro…

The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) used an incorrect boolean expression that combined the RFC 4861 validity checks with the ICMPv6 code check using the wro…

▾ Twilightzephyrproject · zephyrEPSS 0.33%via NVD
GHSA-rjr7-jggh-pgcpHigh
3mo ago

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-3fxj-6jh8-hvhxMedium
3mo ago

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

▾ Sunlitgo-chi · github.com/go-chi/chi/v5/middlewarevia GHSA
CVE-2026-25119High
3mo ago

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers

▾ Twilightgogs · gogs.io/gogsEPSS 0.86%via GHSA
CVE-2026-54782Critical· 10.0
3mo ago

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

▾ MidnightCoreWCF · CoreWCF.PrimitivesEPSS 0.41%via GHSA
CVE-2026-58399Critical
3mo ago

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

▾ Midnightacastellon · @acastellon/authEPSS 0.97%via GHSA
GHSA-38x9-25wx-7fg2High
3mo ago

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

Heimdall: IP Spoofing via Unvalidated Forwarding Headers

▾ Twilighthttps: · https://github.com/dadrus/heimdallvia GHSA
GHSA-gfj5-979r-92pwCritical
3mo ago

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

▾ Midnightacastellon · @acastellon/authvia GHSA
CVE-2026-53857High· 8.1
3mo ago

OpenClaw: Zalo allowFrom could bind to mutable display names

OpenClaw: Zalo allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.37%via GHSA
CVE-2026-53849High· 8.1
3mo ago

OpenClaw: Discord allowFrom could bind to mutable display names

OpenClaw: Discord allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.37%via GHSA
CVE-2026-54308Medium· 7.2
3mo ago

n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

▾ Sunlitn8n · n8nEPSS 0.30%via GHSA
CVE-2026-52845High· 8.1
3mo ago

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

▾ Twilightcaddyserver · github.com/caddyserver/caddy/v2EPSS 0.45%via GHSA
GHSA-p44v-rx83-vjp4High· 8.1
3mo ago

Duplicate Advisory: Discord allowFrom could bind to mutable display names

Duplicate Advisory: Discord allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawvia GHSA
GHSA-w7m7-3xcf-mp48High· 8.1
3mo ago

Duplicate Advisory: Zalo allowFrom could bind to mutable display names

Duplicate Advisory: Zalo allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawvia GHSA
CVE-2026-49468Critical· 9.8PoC
3mo ago

LiteLLM: Authentication Bypass via Host Header Injection

LiteLLM: Authentication Bypass via Host Header Injection

▾ Abyssallitellm · litellmEPSS 0.82%via OSV
CVE-2026-47737High· 7.5
3mo ago

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

Puma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent Connections

▾ Twilightpuma · pumaEPSS 0.27%via GHSA
CVE-2026-48567Critical· 10.0
3mo ago

Azure HorizonDB Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure HorizonDBEPSS 0.92%via CVEORG
CVE-2026-8644Critical· 9.1
3mo ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

▾ Midnightibm · websphere_application_serverEPSS 0.47%via NVD
CVE-2026-44649Critical· 9.8
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…

▾ MidnightEPSS 0.29%via NVD
CVE-2026-8963High· 7.5
4mo ago

Spoofing issue in the Web Speech component

Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Twilightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-8961Medium· 6.5
4mo ago

Spoofing issue in the Form Autofill component

Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.

▾ Sunlitmozilla · firefoxEPSS 0.35%via NVD
CVE-2026-40460Medium· 6.5
4mo ago

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which h…

When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting.  Note: Software versions which h…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-44118High· 7.8
4mo ago

OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header

OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the s…

▾ TwilightOpenClaw · OpenClawEPSS 0.16%via CVEORG
CVE-2026-40575Critical· 9.1
5mo ago

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

▾ Midnightoauth2-proxy · github.com/oauth2-proxy/oauth2-proxy/v7EPSS 0.73%via OSV
CVE-2026-3902High· 7.5
5mo ago

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) t…

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) t…

▾ Twilightdjangoproject · djangoEPSS 0.55%via NVD
CVE-2026-28465Medium· 5.9
6mo ago

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can sp…

▾ Sunlitopenclaw · openclawEPSS 0.68%via NVD
CVE-2026-22797Critical· 9.9
8mo ago

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication …

▾ MidnightOpenStack · keystonemiddlewareEPSS 0.66%via NVD
CVE-2025-27389None
9mo ago

A flaw exists in the verification of application installation sources within ColorOS

A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this issue may cause the risk detection mechanism to fail, which could allow malicious applications to be installed without …

▾ SunlitEPSS 0.13%via NVD
CWE-290 vulnerabilities (CVEs) — page 4 · VulnSea