CWE-346

Origin Validation Error

Parent: CWE-345 - Insufficient Verification of Data Authenticity

The product does not properly verify that the source of data or communication is valid.

684 vulnerabilities with CWE-346
CVE-2026-13868 MEDIUM
Google Chrome < 150.0.7871.47 - Site Isolation Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13840 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Canvas Policy Enforcement
CVSS 6.5
CVE-2026-13839 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via CSS
CVSS 6.5
CVE-2026-13838 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via CSS Implementation
CVSS 6.5
CVE-2026-13826 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Autofill
CVSS 6.5
CVE-2026-13822 MEDIUM
Google Chrome < 150.0.7871.47 - Same Origin Policy Bypass via Malicious Extension
CVSS 6.5
CVE-2026-13793 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via SVG Policy Enforcement
CVSS 6.5
CVE-2026-58169 HIGH
Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code Execution
CVSS 7.5
CVE-2026-43700 MEDIUM
Apple Safari - Origin Validation Error
CVSS 6.5
CVE-2026-46611 MEDIUM
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
CVSS 5.3
CVE-2026-55487 HIGH
pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVSS 7.5
CVE-2026-54030 HIGH
LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow
CVSS 8.0
CVE-2026-54069 CRITICAL
SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
CVE-2026-13034 MEDIUM
Google Chrome - Origin Validation Error
CVSS 4.7
CVE-2026-13022 MEDIUM
Google Chrome < 149.0.7827.197 - Cross-Origin Data Leak via Autofill
CVSS 6.5
CVE-2026-13021 MEDIUM
Google Chrome - Origin Validation Error
CVSS 4.3
CVE-2026-54007 MEDIUM
Open WebUI: Cross-origin postMessage confirmation bypass via action:submit
CVSS 6.5
CVE-2026-55767 MEDIUM
Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle
CVSS 5.8
CVE-2026-50168 HIGH
Angular: URL Parser Differential in @angular/platform-server leading to SSRF Allowlist Bypass
CVSS 8.2
CVE-2026-54665 MEDIUM
Apache NiFi: Missing Validation for Proxy Host Headers
CVSS 5.3
CVE-2026-6734 HIGH
undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
CVSS 7.5
CVE-2026-12304 CRITICAL
Same-origin policy bypass in the Networking: Cookies component
CVSS 9.1
CVE-2026-47825 HIGH
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies in certain situations
CVSS 8.6
CVE-2026-9595 MEDIUM
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
CVSS 5.3
CVE-2026-11624 CRITICAL
Google Mcp Toolbox For Databases < 0.25.0 - Origin Validation Error
Details
Vulnerabilities 684