Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-93682

8 дней назад

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2026-93682

8 дней назад

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2026-93682

8 дней назад

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

CVSS3: 5.8
EPSS: Низкий
msrc логотип

CVE-2026-93682

5 дней назад

Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2026-93682

8 дней назад

When the HTTP stream wrapper follows a redirect and the response carri ...

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-7875-c8px-7q5f

9 дней назад

Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-93682

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

CVSS3: 5.8
0%
Низкий
8 дней назад
redhat логотип
CVE-2026-93682

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

CVSS3: 5.8
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-93682

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

CVSS3: 5.8
0%
Низкий
8 дней назад
msrc логотип
CVE-2026-93682

Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header

CVSS3: 5.8
0%
Низкий
5 дней назад
debian логотип
CVE-2026-93682

When the HTTP stream wrapper follows a redirect and the response carri ...

CVSS3: 5.8
0%
Низкий
8 дней назад
github логотип
GHSA-7875-c8px-7q5f

Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header

CVSS3: 5.3
0%
Низкий
9 дней назад

Уязвимостей на страницу