CVE-2026-46431

MEDIUM

Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: *

Title source: cna
STIX 2.1

Description

Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not preflight and does not send cookies, the wildcard is sufficient to let any third-party page the developer visits open a cross-origin EventSource to the SSE port and read the live filename stream from JavaScript. This vulnerability is fixed in 1.17.7.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 12.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-942
Status published
Products (2)
xyproto/algernon 0 - 1.17.7Go
xyproto/algernon < 1.17.7
Published May 26, 2026
Tracked Since May 26, 2026