Description
podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTML pages with auto-submitting forms containing script payloads in the request body, which are served as text/html due to Go's content type detection, allowing the reflected script to execute in the podinfo origin context when victims visit the attacker's page.
References (3)
Core 3
Core References
Exploit technical-description
exploit
https://github.com/Niccolo10/Security-Advisories/blob/main/CVE-2026-43644/cve-2026-43644.md
Issue Tracking issue-tracking
https://github.com/stefanprodan/podinfo/issues/474
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/podinfo-reflected-xss-via-echo-endpoint
Scores
CVSS v3
5.4
EPSS
0.0019
EPSS Percentile
9.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (3)
stefanprodan/podinfo
< 6.11.12
stefanprodan/podinfo
< 6.11.2
stefanprodan/podinfo
0 - 1.8.1-0.20260519111337-cbebb20fd485Go
Published
May 14, 2026
Tracked Since
May 14, 2026