CWE-441

Unintended Proxy or Intermediary ('Confused Deputy')

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

109 vulnerabilities with CWE-441
CVE-2026-54663 MEDIUM
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVSS 6.1
CVE-2026-43910 HIGH
Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor
CVSS 8.2
CVE-2026-17107 HIGH
Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster
CVSS 8.5
CVE-2026-42933 CRITICAL
Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs
CVSS 10.0
CVE-2026-13062 MEDIUM
MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters
CVSS 6.5
CVE-2026-47122 MEDIUM
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
CVSS 4.2
CVE-2026-16158 HIGH
@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collision
CVSS 8.7
CVE-2026-53514 HIGH
Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin
CVSS 7.7
CVE-2026-53513 CRITICAL
Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
CVSS 9.6
CVE-2026-15183 CRITICAL
Input Validation Vulnerabilities in Snowflake Spark Connector
CVE-2026-56675 HIGH
9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs
CVSS 8.3
CVE-2026-12879 MEDIUM
Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy
CVE-2026-55430 MEDIUM
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
CVSS 5.8
CVE-2026-49086 MEDIUM
Apache Camel Dapr - Pub/Sub Message Rerouting via CloudEvent Headers
CVSS 6.5
CVE-2026-46592 HIGH
Apache Camel CXF - SOAP Operation Redirection via Headers
CVSS 7.5
CVE-2026-53931 MEDIUM
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-50169 MEDIUM
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
CVSS 6.1
CVE-2026-9595 MEDIUM
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
CVSS 5.3
CVE-2026-44494 HIGH
Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
CVSS 8.7
CVE-2026-49821 HIGH
Fission < 1.24.0 Package Builder - Command Execution via Environment Reference
CVSS 7.7
CVE-2026-36608 HIGH
Mercusys AC12G (EU) V1 Firmware AC12G(EU)_V1_200909 - Unauthenticated UPnP Port Forwarding to Admin Interface
CVSS 8.8
CVE-2026-0098 HIGH
Google Android - Unintended Proxy or Intermediary ('Confused Deputy')
CVSS 7.8
CVE-2026-48522 MEDIUM
PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
CVSS 4.2
CVE-2026-3160 MEDIUM
Unintended Proxy or Intermediary ('Confused Deputy') in GitLab
CVSS 5.8
CVE-2026-45003 MEDIUM
OpenClaw < 2026.4.22 - Connector Endpoint Host Override via Workspace dotenv Files
CVSS 5.0
Details
Vulnerabilities 109