Medium severity6.1NVD Advisory· Published Mar 20, 2026· Updated Apr 16, 2026
CVE-2026-31382
CVE-2026-31382
Description
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
27- Tables Turn on 'The Gentlemen' RaaS Gang With Data LeakDark Reading · May 13, 2026
- Thus Spoke…The GentlemenCheck Point Research · May 13, 2026
- 20 Leaders Who Built the CISO Era: 2 Decades of ChangeDark Reading · May 12, 2026
- Is the SOC Obsolete, and We Just Haven’t Admitted It Yet?SecurityWeek · May 12, 2026
- Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadlineThe Register Security · May 11, 2026
- BWH Hotels guests warned after reservation data checks out with cybercrooksThe Register Security · May 11, 2026
- Hackers Use AI for Exploit Development, Attack AutomationDark Reading · May 11, 2026
- Your Purple Team Isn't Purple — It's Just Red and Blue in the Same RoomThe Hacker News · May 11, 2026
- The questionnaire-based TPRM model is broken, and TrustCloud has a fixHelp Net Security · May 11, 2026
- Smart Glasses for the AuthoritiesSchneier on Security · May 7, 2026
- Claude AI Guided Hackers Toward OT Assets During Water Utility IntrusionSecurityWeek · May 7, 2026
- Iran cybersnoops still LARPing as ransomware crooks in espionage opsThe Register Security · May 6, 2026
- MuddyWater hackers use Chaos ransomware as a decoy in attacksBleepingComputer · May 6, 2026
- Muddying the Tracks: The State-Sponsored Shadow Behind Chaos RansomwareRapid7 Blog · May 6, 2026
- MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware AttackThe Hacker News · May 6, 2026
- ServiceNow clears agents for landing with new AI control towerThe Register Security · May 5, 2026
- Vimeo data breach exposes personal information of 119,000 peopleBleepingComputer · May 5, 2026
- We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually IsThe Hacker News · May 5, 2026
- Cybersecurity jobs available right now: May 5, 2026Help Net Security · May 5, 2026
- They don’t hack, they borrow: How fraudsters target credit unionsBleepingComputer · May 4, 2026
- OpenAI Rolls Out Advanced Security for ChatGPT AccountsSecurityWeek · May 4, 2026
- ChatGPT advanced account security adds passkeys and hardware keysHelp Net Security · May 3, 2026
- TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)SANS Internet Storm Center · Apr 27, 2026
- UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW MalwareThe Hacker News · Apr 23, 2026
- Ransomware Negotiator Pleads Guilty to BlackCat SchemeDark Reading · Apr 21, 2026
- Project Glasswing and the Next Challenge for Defenders: Turning Faster Discovery into Faster ActionRapid7 Blog · Apr 20, 2026
- The Increasing Role of AI in Vulnerability ResearchWordfence Blog · Apr 10, 2026