VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
Loading...
Loading...
Score 6.5 from GitHub Security Advisory published 2026-05-07. NVD baseline CVSS 6.5; sources differ by 0.0.
VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use the from address for automated actions such as Ticket creation or Ticket updates.
May 7, 2026
May 8, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-8142
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.