VulnSea

CWE-348

CVEs classified under CWE-348, newest first.

19 CVEsRSS

CVE-2026-62987Medium· 5.8PoC
yesterday

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

Twilightfabiolb · fabiovia NVD
CVE-2026-61682Critical· 9.9
4d ago

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…

Midnightkcp-dev · kcpEPSS 0.28%via NVD
CVE-2026-61589Medium· 6.3
6d ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

Sunlitdjust-org · djustEPSS 0.16%via NVD
CVE-2026-92395Critical· 9.1
6d ago

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IP…

Midnight@fastify/proxy-addr · @fastify/proxy-addrEPSS 0.30%via NVD
CVE-2026-90711Critical· 9.1
1w ago

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with …

Midnightproxy-addr · proxy-addrEPSS 0.19%via NVD
CVE-2026-90679Medium· 4.3
1w ago

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an …

SunlitForgejo · ForgejoEPSS 0.16%via NVD
CVE-2026-16272Critical· 9.1
1w ago

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API …

MidnightPayTR Payment and Electronic Money Institution Inc. · PayTR Virtual Pos iFrame API (v9x) WHMCS ModuleEPSS 0.14%via NVD
CVE-2026-16732Medium· 6.1
2w ago

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

Sunlitfastify · fastifyEPSS 0.14%via GHSA
CVE-2026-48061Medium· 5.9
1mo ago

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whiteli…

Sunlitlitestar · litestarEPSS 0.34%via NVD
CVE-2026-25552Low· 3.7
1mo ago

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers…

SunlitEPSS 0.17%via NVD
CVE-2026-63220Medium· 4.8
1mo ago

CodeIgniter is a PHP full-stack web framework

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers an…

Sunlitcodeigniter4 · codeigniter4/frameworkEPSS 0.14%via NVD
CVE-2026-59897Medium· 4.8
2mo ago

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

Sunlithono · honoEPSS 0.18%via GHSA
CVE-2026-63770High· 7.5
2mo ago

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request…

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request…

TwilightEPSS 0.29%via NVD
CVE-2026-55641High· 8.2
2mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypas…

TwilightEPSS 0.32%via NVD
CVE-2026-58122Critical· 9.1
2mo ago

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header wi…

Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header wi…

MidnightEPSS 0.37%via NVD
CVE-2026-46466Low· 2.7
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less t…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of less t…

SunlitEPSS 0.15%via NVD
GHSA-rjr7-jggh-pgcpHigh
2mo ago

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
CVE-2026-12249Critical· 9.0
3mo ago

Canonical ADSys Uses a Less Trusted Source

Canonical ADSys Uses a Less Trusted Source

Midnightubuntu · github.com/ubuntu/adsysEPSS 0.14%via GHSA
CVE-2026-54289Medium· 4.8
3mo ago

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

Sunlithono · honoEPSS 0.18%via GHSA
CWE-348 vulnerabilities (CVEs) · VulnSea