VulnSea

CWE-346

CVEs classified under CWE-346, newest first.

110 CVEsRSS

CVE-2026-81100Medium· 6.8
3w ago

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the t…

SunlitEPSS 0.16%via NVD
CVE-2026-81095Medium· 6.8
3w ago

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport …

SunlitEPSS 0.16%via NVD
GHSA-qh7h-6c7g-x8m6Critical· 5.4
3w ago

Duplicate Advisory: Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Duplicate Advisory: Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Midnightgetgrav · getgrav/gravvia GHSA
CVE-2026-55637High
3w ago

genieacs-mcp is an MCP server for GenieACS written in Go

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKE…

Twilightgeiserx · github.com/geiserx/genieacs-mcpEPSS 0.21%via NVD
CVE-2026-55529Medium· 6.9
3w ago

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

Sunlitpraisonai · praisonaiEPSS 0.12%via OSV
CVE-2026-55532High· 7.6
3w ago

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

Twilightpraisonai · praisonaiEPSS 0.13%via OSV
CVE-2026-53499High· 7.2
1mo ago

FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data

FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegat…

TwilightNICMx · FORT-validatorEPSS 0.16%via NVD
CVE-2026-62316High· 8.8PoC
1mo ago

Microsoft UFO open-source framework for intelligent automation across devices and platforms

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate t…

Midnightmicrosoft · UFOEPSS 0.36%via NVD
CVE-2026-67448Medium· 6.5
1mo ago

Mailpit is an email testing tool and API for developers

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path,…

Sunlitaxllent · github.com/axllent/mailpitEPSS 0.15%via NVD
CVE-2026-74960High· 8.1⚖ disputed
1mo ago

Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.16%via NVD
CVE-2026-74934High· 7.5
1mo ago

Site isolation issue in the Graphics: CanvasWebGL component

Site isolation issue in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.16%via NVD
CVE-2026-73419Medium· 6.8
1mo ago

NextAuth.js provides authentication for Next.js

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound t…

Sunlitnextauthjs · next-authEPSS 0.19%via NVD
CVE-2026-15141Medium· 5.7
1mo ago

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficie…

The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficie…

Sunlittp-link · tl-wr820n_firmwareEPSS 0.12%via NVD
CVE-2026-56179High· 8.3
1mo ago

Windows Network Address Translation (NAT) Spoofing Vulnerability

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

TwilightMicrosoft · Windows 11 Version 24H2EPSS 0.23%via CVEORG
CVE-2026-46409Critical· 9.6
1mo ago

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without ser…

MidnightEPSS 0.36%via NVD
CVE-2026-47194None
1mo ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled request Host header, allowing a remote attacker to cause emailed login links to point t…

SunlitEPSS 0.20%via NVD
CVE-2026-70599Medium· 5.9
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level …

Sunlitelectron · electronEPSS 0.18%via NVD
CVE-2026-66318High· 8.1
1mo ago

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.24%via CVEORG
CVE-2026-66316Medium· 5.4
1mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.14%via CVEORG
CVE-2026-66313Medium· 6.8
1mo ago

Microsoft Edge (Chromium-based) Tampering Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.17%via CVEORG
CVE-2026-66317Medium· 5.4
1mo ago

Microsoft Edge (Chromium-based) Tampering Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.14%via CVEORG
CVE-2026-66322High· 7.1
1mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.15%via CVEORG
CVE-2026-69245Medium· 6.5
1mo ago

Guzzle is an extensible PHP HTTP client

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric hos…

Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.14%via NVD
CVE-2026-48063Critical
1mo ago

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event…

Midnightbaileys · baileysEPSS 0.16%via NVD
CVE-2026-66420High· 8.8
1mo ago

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the C…

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the C…

TwilightYlianst · MeshCentralEPSS 0.17%via NVD
CVE-2026-63118Medium
1mo ago

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection

Sunlitmcp · mcpEPSS 0.19%via GHSA
CVE-2026-54605High· 7.2
1mo ago

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and foll…

Twilightoauth · oauthEPSS 0.13%via NVD
CVE-2026-57989High· 7.4
1mo ago

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.29%via NVD
CVE-2026-57978Medium· 5.4
1mo ago

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.14%via NVD
CVE-2026-16745High· 8.8
2mo ago

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI)

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbit…

TwilightRed Hat · rhoai/odh-dashboard-rhel9EPSS 0.45%via NVD
CWE-346 vulnerabilities (CVEs) — page 2 · VulnSea