VulnSea

CWE-346

CVEs classified under CWE-346, newest first.

131 CVEsRSS

CVE-2026-55767Medium· 5.8
3mo ago

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

guzzlehttp/guzzle: Dot-Only Cookie Domains Match All Hosts

▾ Sunlitguzzlehttp · guzzlehttp/guzzleEPSS 0.21%via GHSA
GHSA-v52w-28xh-v562High
3mo ago

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

Kozou: Unauthenticated MCP HTTP server and bundled dev-stack hardening (DNS-rebinding, request-body limits, read-only reads, default network exposure)

▾ Twilightkozou · kozouvia GHSA
GHSA-x845-2f78-7v36High· 8.6
3mo ago

Blocky DNSSEC validation bypass and validation-cache scope pollution

Blocky DNSSEC validation bypass and validation-cache scope pollution

▾ Twilight0xERR0R · github.com/0xERR0R/blockyvia GHSA
CVE-2026-55791Critical
3mo ago

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

▾ Midnightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
CVE-2026-55660High
3mo ago

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover

▾ Twilighttinacms · tinacmsEPSS 0.28%via GHSA
GHSA-v3f4-w7r7-v3hmHigh
3mo ago

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests

▾ Twilightzenalexa · @zenalexa/uniclivia GHSA
GHSA-f4xh-w4cj-qxq8High· 7.7
3mo ago

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

LangSmith SDK TracingMiddleware: Arbitrary server-side file read

▾ Twilightlangsmith · langsmithvia GHSA
GHSA-869j-r97x-hx2gHigh
3mo ago

Anki's local HTTP server does not sufficiently validate requests

Anki's local HTTP server does not sufficiently validate requests

▾ Twilightaqt · aqtvia GHSA
CVE-2026-55669Medium· 4.2
3mo ago

ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider

ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.15%via GHSA
GHSA-vmf9-xx9w-86wxHigh· 8.3
3mo ago

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered tools

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
CVE-2026-54007High
3mo ago

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

Open WebUI: Cross-origin postMessage confirmation bypass via action:submit

▾ Twilightopen-webui · open-webuiEPSS 0.23%via GHSA
CVE-2026-9595Medium· 5.3
3mo ago

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

▾ Sunlitwebpack-dev-server · webpack-dev-serverEPSS 0.23%via GHSA
CVE-2026-6734High· 7.5
3mo ago

undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)

A flaw was found in undici. When using Socks5ProxyAgent, undici incorrectly reuses a single connection pool across different origins. This can lead to cross-origin request routing, where sensitive credentials and data intended for one dest…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.39%via CSAF
CVE-2026-50168High
3mo ago

@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass

@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass

▾ Twilightangular · @angular/platform-serverEPSS 0.24%via GHSA
GHSA-j9gf-vw2f-9hrwHigh· 8.1
3mo ago

Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation

Appsmith: Configuration-dependent origin validation bypass in password reset and email verification link generation

▾ Twilightappsmith · com.appsmith:servervia GHSA
CVE-2026-47691High· 8.7
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the bailiwick of NS records, enabling DNS Ca…

▾ Twilightnetty · nettyEPSS 0.36%via NVD
CVE-2026-45674High· 8.7PoC
3mo ago

Netty is a network application framework for development of protocol servers and clients

Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bailiwick) of CNAME records in DNS respon…

▾ Midnightnetty · nettyEPSS 0.36%via NVD
CVE-2026-41700High· 8.1
3mo ago

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbi…

▾ Twilightvmware · spring_for_graphqlEPSS 0.23%via NVD
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

▾ Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-6657High· 8.8
3mo ago

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use of `re.match()` for validating the `Ori…

▾ Twilightjupyter · jupyter_serverEPSS 0.27%via NVD
CVE-2026-44649Critical· 9.8
4mo ago

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Auth…

▾ MidnightEPSS 0.29%via NVD
CVE-2026-8971Medium· 6.5
4mo ago

Same-origin policy bypass in the Networking: JAR component

Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.

▾ Sunlitmozilla · firefoxEPSS 0.17%via NVD
CVE-2026-46728High· 8.2
4mo ago

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.

▾ Twilightdenx · u-bootEPSS 0.13%via NVD
CVE-2026-6276High· 7.5PoC⚖ disputed
4mo ago

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information…

▾ Midnighthaxx · curlEPSS 0.35%via NVD
CVE-2026-5918Medium· 4.3
5mo ago

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.21%via NVD
CVE-2026-5899Medium· 6.1
5mo ago

Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

▾ Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-37977Low· 3.7
5mo ago

A flaw was found in Keycloak

A flaw was found in Keycloak. A remote attacker can exploit a Cross-Origin Resource Sharing (CORS) header injection vulnerability in Keycloak's User-Managed Access (UMA) token endpoint. This flaw occurs because the `azp` claim from a cli…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-34373High· 8.8
6mo ago

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditiona…

▾ Twilightparseplatform · parse-serverEPSS 0.24%via NVD
CVE-2026-34359High· 7.4
6mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server U…

▾ Twilighthapifhir · hl7_fhir_coreEPSS 0.20%via NVD
CVE-2026-25604Medium· 5.4PoC
6mo ago

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

In AWS Auth manager, the origin of the SAML authentication has been used as provided by the client and not verified against the actual instance URL.  This allowed to gain access to different instances with potentially different access co…

▾ Twilightapache · apache-airflow-providers-amazonEPSS 0.51%via NVD
CWE-346 vulnerabilities (CVEs) — page 4 · VulnSea