VulnSea

CWE-565

CVEs classified under CWE-565, newest first.

6 CVEsRSS

CVE-2026-76186Critical· 9.1
5d ago

Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separa…

Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separa…

Midnightapache · apache-airflow-providers-keycloakEPSS 0.79%via NVD
CVE-2026-69215Medium· 6.8
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanchored substring checks instead of RFC 6265 domain and path matching when deciding whether to attach a stored cookie.…

Sunlithttp4s · org.http4s:http4s-client_2.12EPSS 0.43%via NVD
CVE-2026-69214Medium· 6.8
6d ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…

Sunlithttp4s · http4sEPSS 0.26%via NVD
CVE-2026-8924Critical· 9.1PoC⚖ disputed
2mo ago

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmit…

Abyssalhaxx · curlEPSS 0.66%via NVD
CVE-2026-53871High· 8.1
3mo ago

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_pr…

Twilightnesquena · hermes-webuiEPSS 0.36%via NVD
CVE-2020-26955Medium· 6.5
5y ago

When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in privat…

When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in privat…

Sunlitmozilla · firefox_mobileEPSS 0.83%via NVD
CWE-565 vulnerabilities (CVEs) · VulnSea