VYPR

CWE-346

Origin Validation Error

ClassDraft

Description

The product does not properly verify that the source of data or communication is valid.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-111 · CAPEC-141 · CAPEC-142 · CAPEC-160 · CAPEC-21 · CAPEC-384 · CAPEC-385 · CAPEC-386 · CAPEC-387 · CAPEC-388 · CAPEC-510 · CAPEC-59 · CAPEC-60 · CAPEC-75 · CAPEC-76 · CAPEC-89

CVEs mapped to this weakness (729)

page 25 of 37
  • CVE-2026-15141MedAug 12, 2026
    risk 0.34cvss epss 0.00

    The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful…

  • CVE-2026-54665MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host header without validating the values provided. Apache NiFi 1.6.0 introduced a configurable application property to restrict…

  • CVE-2026-43972MedJun 8, 2026
    risk 0.34cvss epss 0.00

    Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unvalidated HTTP/2 PUSH_PROMISE authority. In gun_http2:push_promise_frame/7, the :authority pseudo-header from an incoming PUSH_PROMISE frame is stored verbatim…

  • CVE-2026-6143MedApr 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive cross-domain policy with untrusted…

  • CVE-2026-27824MedFeb 27, 2026
    risk 0.34cvss 5.3epss 0.00

    calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the…

  • CVE-2026-1997MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an…

  • CVE-2025-12245MedOct 27, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in chatwoot up to 4.7.0. This vulnerability affects the function initPostMessageCommunication of the file app/javascript/sdk/IFrameHelper.js of the component Widget. The manipulation of the argument baseUrl leads to origin validation error. Remote…

  • CVE-2025-52621MedAug 15, 2025
    risk 0.34cvss 5.3epss 0.00

    HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning.  The BigFix SaaS's HTTP responses were observed to include the Origin header. Its presence alongside an unvalidated reflection of the Origin header value introduces a potential for cache poisoning.

  • CVE-2025-42998MedJun 10, 2025
    risk 0.34cvss 5.3epss 0.00

    The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and…

  • CVE-2024-56170MedDec 18, 2024
    risk 0.34cvss 5.3epss 0.00

    A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest should be prioritized over other…

  • CVE-2024-44212MedDec 12, 2024
    risk 0.34cvss 5.3epss 0.00

    A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, tvOS 18.1, visionOS 2.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.

  • CVE-2024-51072MedNov 22, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset UDS service. NOTE: this is disputed by the Supplier because the findings came from a potentially unrealistic test environment (an…

  • CVE-2024-51037MedNov 15, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

  • CVE-2024-10460MedOct 29, 2024
    risk 0.34cvss 5.3epss 0.00

    The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

  • CVE-2024-6301MedJun 25, 2024
    risk 0.34cvss 5.3epss 0.00

    Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

  • CVE-2024-25996MedMar 12, 2024
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

  • CVE-2023-30996MedFeb 26, 2024
    risk 0.34cvss 5.3epss 0.00

    IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different origins. IBM X-Force ID: 254290.

  • CVE-2023-4045MedAug 1, 2023
    risk 0.34cvss 5.3epss 0.01

    Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

  • CVE-2023-32553MedJun 26, 2023
    risk 0.34cvss 5.3epss 0.00

    An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certain circumstances to disclose sensitive information on agents. This is similar to, but not identical to CVE-2023-32552.

  • CVE-2023-28318MedMay 9, 2023
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of the Message_KeepHistory or Message_ShowDeletedStatus server configuration. This allows users to bypass the intended message deletion behavior, hiding messages and deletion notices.