The product does not properly verify that the source of data or communication is valid.
684 vulnerabilities with CWE-346
CVE-2026-17693
MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via FileSystem Policy Enforcement
CVSS 4.3
CVE-2026-17662
MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Prefetch Policy Enforcement
CVSS 4.3
CVE-2026-6102
HIGH
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-63118
MEDIUM
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
CVE-2026-54605
HIGH
OAuth: Cross-origin token-request redirects can expose signed request metadata
CVSS 7.2
CVE-2026-57989
HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-57978
MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVSS 5.4
CVE-2026-16745
HIGH
Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation
CVSS 8.8
CVE-2026-13321
HIGH
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVSS 8.6
CVE-2026-16399
HIGH
Site isolation issue in the DOM: Navigation component
CVSS 7.5
CVE-2026-16398
HIGH
Mozilla Firefox - Site Isolation Issue in the Graphics Component
CVSS 7.5
CVE-2026-16387
CRITICAL
Mozilla Firefox - Site Isolation Issue in the Networking Component
CVSS 9.8
CVE-2026-16381
CRITICAL
Same-origin policy bypass in the Networking: DNS component
CVSS 9.1
CVE-2026-16375
CRITICAL
Site isolation issue in the Networking: HTTP component
CVSS 9.8
CVE-2026-16358
CRITICAL
Site isolation issue in the Graphics: WebRender component
CVSS 9.8
CVE-2026-16349
CRITICAL
Same-origin policy bypass in the DOM: Navigation component
CVSS 9.8
CVE-2026-46701
HIGH
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
CVSS 7.6
CVE-2026-46555
HIGH
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVSS 7.7
CVE-2026-48022
MEDIUM
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVSS 6.5
CVE-2026-59950
HIGH
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVSS 8.1
CVE-2026-52843
CRITICAL
Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode
CVSS 9.3
CVE-2026-52842
CRITICAL
Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass
CVSS 9.3
CVE-2026-47703
MEDIUM
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVSS 5.3
CVE-2026-15775
MEDIUM
Google Chrome < 150.0.7871.125 - Same Origin Policy Bypass via V8 Inappropriate Implementation
CVSS 6.5
CVE-2026-15768
MEDIUM
Google Chrome < 150.0.7871.125 - Same Origin Policy Bypass via HTML-in-Canvas
CVSS 6.5
Details
Vulnerabilities
684