CWE-346
CVEs classified under CWE-346, newest first.
131 CVEsRSS
CVE-2026-55767Medium· 5.8guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts
GHSA-v52w-28xh-v562HighKozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)
GHSA-x845-2f78-7v36High· 8.6Blocky DNSSEC validation bypass and validation-cache scope pollution
Blocky DNSSEC validation bypass and validation-cache scope pollution
CVE-2026-55791CriticalCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
CVE-2026-55660HighTinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
GHSA-v3f4-w7r7-v3hmHighUni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests
GHSA-f4xh-w4cj-qxq8High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
GHSA-869j-r97x-hx2gHighAnki's local HTTP server does not sufficiently validate requests
Anki's local HTTP server does not sufficiently validate requests
CVE-2026-55669Medium· 4.2ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
GHSA-vmf9-xx9w-86wxHigh· 8.3PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools
CVE-2026-54007HighOpen WebUI: Cross-origin postMessage confirmation bypass via action:submit
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVE-2026-9595Medium· 5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
CVE-2026-6734High· 7.5undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)
A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…
CVE-2026-50168High@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
GHSA-j9gf-vw2f-9hrwHigh· 8.1Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation
CVE-2026-47691High· 8.7Netty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…
CVE-2026-45674High· 8.7PoCNetty is a network application framework for development of protocol servers and clients
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…
CVE-2026-41700High· 8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbi…
CVE-2026-48022Medium· 6.5@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVE-2026-6657High· 8.8A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Ori…
CVE-2026-44649Critical· 9.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…
CVE-2026-8971Medium· 6.5Same-origin policy bypass in the Networking: JAR component
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
CVE-2026-46728High· 8.2Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
CVE-2026-6276High· 7.5PoC⚖ disputedUsing libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…
CVE-2026-5918Medium· 4.3Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page
Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
CVE-2026-5899Medium· 6.1Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …
CVE-2026-37977Low· 3.7A flaw was found in Keycloak
A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a cli…
CVE-2026-34373High· 8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditiona…
CVE-2026-34359High· 7.4HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server U…
CVE-2026-25604Medium· 5.4PoCIn AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…
In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL. This allowed to gain access to different instances with potentially different access co…