CVE-2026-35507
MEDIUMShynet <0.14.0 - Host Header Injection
Title source: llmDescription
Shynet before 0.14.0 allows Host header injection in the password reset flow.
Scores
CVSS v3
6.4
EPSS
0.0001
EPSS Percentile
2.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Details
CWE
CWE-348
Status
published
Products (2)
milesmcc/Shynet
< 0.14.0
shynet/shynet
< 0.13.1
Published
Apr 03, 2026
Tracked Since
Apr 03, 2026