CWE-346— Origin Validation Error
The product does not properly verify that the source of data or communication is valid.— MITRE CWE catalog
836 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-346page 11 of 17
- CVE-2019-13740MEDIUMCVSS 6.5EG 6.52019-12-10
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- CVE-2019-13664MEDIUMCVSS 6.5EG 6.52019-11-25
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2019-16275MEDIUMCVSS 6.5EG 6.52019-09-12
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (ak…
- CVE-2019-5834MEDIUMCVSS 6.5EG 6.52019-06-27
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- CVE-2018-18499MEDIUMCVSS 6.5EG 6.52019-02-28
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation an…
- CVE-2018-18494MEDIUMCVSS 6.5EG 6.52019-02-28
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and cou…
- CVE-2018-12402MEDIUMCVSS 6.5EG 6.52019-02-28
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visi…
- CVE-2019-5773MEDIUMCVSS 6.5EG 6.52019-02-19
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
- CVE-2018-16072MEDIUMCVSS 6.5EG 6.52019-01-09
A missing origin check related to HLS manifests in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2026-107292MEDIUMCVSS 6.4EG 6.42026-10-08
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 2.30.0, the Agent.to_web() and clai web development chat server does not validate the Host header, allowing a website vis…
- CVE-2026-33586MEDIUMCVSS 6.3EG 6.32026-10-07
Authenticated users are able to manipulate both the SMTP envelope “Envelope-from” and “From” fields when sending emails through OVH mail servers. Due to OVH's default SPF configuration, which commonly includes include:mx.ovh.com…
- CVE-2026-92360MEDIUMCVSS 6.3EG 6.32026-09-16
A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_START…
- CVE-2026-69559MEDIUMCVSS 6.3EG 6.32026-09-08
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
- CVE-2026-53656MEDIUMCVSS 6.3EG 6.32026-07-15
FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media route in fiftyone/server/routes/media.py unconditionally ret…
- CVE-2026-11181MEDIUMCVSS 6.3EG 6.32026-06-04
Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-9989MEDIUMCVSS 6.3EG 6.32026-05-28
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High)
- CVE-2026-6143MEDIUMCVSS 6.3EG 6.32026-04-13
A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functionality of the file src-tauri/src/proxy/server.rs of the component ProxyServer. The manipulation results in permissive c…
- CVE-2026-33697MEDIUMCVSS 6.3EG 6.32026-03-27
Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulnerable to a relay attack affecting all versions from v0.4.0 through v0.8.2. This vulnerability is present in both the AMD…
- CVE-2026-21790MEDIUMCVSS 6.3EG 6.32026-03-24
HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to bypass additional authentication checks.
- CVE-2025-11304MEDIUMCVSS 6.3EG 6.32025-10-05
A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability is an unknown functionality of the component API. Executing manipulation can lead to permissive cross-domain policy with untrusted domains. T…
- CVE-2025-21542MEDIUMCVSS 6.3EG 6.32025-01-21
Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security). Supported versions that are affected are 7.4.0, 7.4.1 and 7.5.0. Easily exploitable vulnerabilit…
- CVE-2024-22062MEDIUMCVSS 6.3EG 6.32024-07-09
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
- CVE-2024-37661MEDIUMCVSS 6.3EG 6.32024-06-17
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.
- CVE-2024-0009MEDIUMCVSS 6.3EG 6.32024-02-14
An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a VPN connection from an unauthorized IP address.
- CVE-2019-19545MEDIUMCVSS 6.3EG 6.32019-12-05
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the …
- CVE-2019-18381MEDIUMCVSS 6.3EG 6.32019-12-05
Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, which is a type of issue that allows restricted resources on a web page to be requested from another domain outside the …
- CVE-2023-3581MEDIUMCVSS 6.2EG 6.22023-07-17
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM attacker on Mattermost to access the websocket APIs.
- CVE-2026-59883MEDIUMCVSS 6.1EG 6.12026-07-08
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix mat…
- CVE-2026-5899MEDIUMCVSS 6.1EG 6.12026-04-08
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML pa…
- CVE-2026-34083MEDIUMCVSS 6.1EG 6.12026-04-02
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server contains a code-level vulnerability in its OIDC login and logout handlers where the unvalidated HTTP Host header is used …
- CVE-2026-22694MEDIUMCVSS 6.1EG 6.12026-01-14
AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a m…
- CVE-2024-14006MEDIUMCVSS 6.1EG 6.12025-10-30
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote atta…
- CVE-2019-11762MEDIUMCVSS 6.1EG 6.12020-01-08
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbir…
- CVE-2018-10591MEDIUMCVSS 6.1EG 6.12018-05-15
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin valid…
- CVE-2003-0981MEDIUMCVSS 6.1EG 6.12004-01-05
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site scripting (XSS) attacks.
- CVE-2025-66593MEDIUMCVSS 5.6EG 6.12026-05-27
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
- CVE-2025-66592MEDIUMCVSS 5.6EG 6.12026-05-27
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
- CVE-2025-13593MEDIUMCVSS 5.6EG 6.12026-05-27
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
- CVE-2023-44190MEDIUMCVSS 5.4EG 6.12023-10-11
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10001, PTX10004, PTX10008, and PTX10016 devices allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addres…
- CVE-2023-44189MEDIUMCVSS 5.4EG 6.12023-10-11
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS Evolved on PTX10003 Series allows a network-adjacent attacker to bypass MAC address checking, allowing MAC addresses not intended to reach the adjac…
- CVE-2026-46685MEDIUMCVSS 6.0EG 6.02026-05-28
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origin value back as Access-Control-Allow-Ori…
- CVE-2026-77119MEDIUMCVSS 5.9EG 5.92026-09-16
A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 t…
- CVE-2026-66732MEDIUMCVSS 5.9EG 5.92026-08-06
Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections are resolved by a two-byte local connection handle alone without verifying that the datagram…
- CVE-2026-70599MEDIUMCVSS 5.9EG 5.92026-08-05
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, serial-port and media permission checks made from an iframe passed the top-level fr…
- CVE-2026-32318MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man-in-t…
- CVE-2026-32317MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacker tamper with the vault configuration file leading to a man…
- CVE-2026-32303MEDIUMCVSS 5.9EG 5.92026-03-20
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration file leading to a man-in-the-middle vulnerability in Hub ke…
- CVE-2026-32632MEDIUMCVSS 5.9EG 5.92026-03-18
Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the MCP endpoint, but prior to version 4.5.2, the main REST/WebUI FastAPI application still accepts arbitrary `Host` heade…
- CVE-2023-2589MEDIUMCVSS 5.9EG 5.92023-06-07
An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a p…
- CVE-2023-22899MEDIUMCVSS 5.9EG 5.92023-01-10
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
Map vulnerabilities like CWE-346 to your infrastructure
EchelonGraph correlates every CVE — across CWE-346 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →