VYPR

Nukeviet

by WordPress

CVEs (1)

  • CVE-2026-55372higJul 13, 2026
    risk 0.45cvss epss

    ## Summary An unauthenticated attacker can coerce the server into issuing HTTP requests to an attacker-chosen host by spoofing the `X Forwarded-Host` (and `X-Forwarded-Proto`) request headers. The forwarded host is used, without validation, to build the URL that…