CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

684 vulnerabilities with CWE-346
CVE-2026-56181 HIGH
Microsoft Windows 11 Version 24H2 - Windows Network Address Translation (NAT) Spoofing Vulnerability
CVSS 8.3
CVE-2026-15076 HIGH
Eclipse Vert.x - Origin Validation Error
CVSS 7.5
CVE-2026-15075 HIGH
Eclipse Vert.x - Exposure of Sensitive Information to an Unauthorized Actor
CVSS 7.5
CVE-2026-55669 MEDIUM
ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider
CVSS 4.2
CVE-2026-59208 MEDIUM
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
CVSS 6.8
CVE-2026-59723 HIGH
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)
CVSS 8.8
CVE-2026-59883 MEDIUM
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
CVSS 4.7
CVE-2026-55438 MEDIUM
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
CVSS 5.8
CVE-2026-59153 LOW
Anki's local HTTP server does not sufficiently validate requests
CVE-2026-58266 MEDIUM
Anki: User scripts in iframes have access to the internal Anki API
CVSS 6.5
CVE-2026-34198 MEDIUM
Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing
CVSS 5.3
CVE-2026-42341 CRITICAL
FOSSBilling has an unauthenticated payment bypass via IPN callback forgery
CVE-2026-59152 MEDIUM
Arbitrary server-side file read in LangSmith SDK TracingMiddleware
CVSS 5.0
CVE-2026-59096 HIGH
Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forwarded-Host
CVSS 7.5
CVE-2026-55660 HIGH
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
CVE-2026-56277 MEDIUM
Flowise - Hardcoded CORS Wildcard in TTS Endpoint
CVSS 6.5
CVE-2026-14105 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via Speech Policy Enforcement
CVSS 4.3
CVE-2026-14079 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-14057 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via FedCM
CVSS 4.3
CVE-2026-14053 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Extensions Policy Bypass
CVSS 4.3
CVE-2026-14046 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via CustomTabs
CVSS 4.3
CVE-2026-14039 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via GetUserMedia
CVSS 4.3
CVE-2026-13913 MEDIUM
Google Chrome < 150.0.7871.47 - Insufficient Policy Enforcement in Autofill
CVSS 6.5
CVE-2026-13887 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via NFC Implementation
CVSS 6.5
CVE-2026-13881 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via WebAppInstalls
CVSS 6.5
Details
Vulnerabilities 684