CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

684 vulnerabilities with CWE-346
CVE-2026-17693 MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via FileSystem Policy Enforcement
CVSS 4.3
CVE-2026-17662 MEDIUM
Google Chrome < 151.0.7922.72 - Cross-Origin Data Leak via Prefetch Policy Enforcement
CVSS 4.3
CVE-2026-6102 HIGH
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability
CVSS 7.8
CVE-2026-63118 MEDIUM
MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection
CVE-2026-54605 HIGH
OAuth: Cross-origin token-request redirects can expose signed request metadata
CVSS 7.2
CVE-2026-57989 HIGH
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVSS 7.4
CVE-2026-57978 MEDIUM
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVSS 5.4
CVE-2026-16745 HIGH
Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation
CVSS 8.8
CVE-2026-13321 HIGH
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVSS 8.6
CVE-2026-16399 HIGH
Site isolation issue in the DOM: Navigation component
CVSS 7.5
CVE-2026-16398 HIGH
Mozilla Firefox - Site Isolation Issue in the Graphics Component
CVSS 7.5
CVE-2026-16387 CRITICAL
Mozilla Firefox - Site Isolation Issue in the Networking Component
CVSS 9.8
CVE-2026-16381 CRITICAL
Same-origin policy bypass in the Networking: DNS component
CVSS 9.1
CVE-2026-16375 CRITICAL
Site isolation issue in the Networking: HTTP component
CVSS 9.8
CVE-2026-16358 CRITICAL
Site isolation issue in the Graphics: WebRender component
CVSS 9.8
CVE-2026-16349 CRITICAL
Same-origin policy bypass in the DOM: Navigation component
CVSS 9.8
CVE-2026-46701 HIGH
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
CVSS 7.6
CVE-2026-46555 HIGH
WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration
CVSS 7.7
CVE-2026-48022 MEDIUM
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects
CVSS 6.5
CVE-2026-59950 HIGH
MCP Python SDK: WebSocket server transport does not support Host/Origin validation
CVSS 8.1
CVE-2026-52843 CRITICAL
Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode
CVSS 9.3
CVE-2026-52842 CRITICAL
Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass
CVSS 9.3
CVE-2026-47703 MEDIUM
AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle
CVSS 5.3
CVE-2026-15775 MEDIUM
Google Chrome < 150.0.7871.125 - Same Origin Policy Bypass via V8 Inappropriate Implementation
CVSS 6.5
CVE-2026-15768 MEDIUM
Google Chrome < 150.0.7871.125 - Same Origin Policy Bypass via HTML-in-Canvas
CVSS 6.5
Details
Vulnerabilities 684