Showing 1 vulnerability on this page for secure_headers

Signals CISA KEV Ransomware Nuclei
GitHub vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input

secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \r, or \n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :repor

CWE-113CWE-79Jul 17, 2026
CVSS4.7v3.1EPSS0.174%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX