CWE-441— Unintended Proxy or Intermediary (Confused Deputy)
The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.— MITRE CWE catalog
193 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-441page 4 of 4
- CVE-2026-3160MEDIUMCVSS 5.8EG 5.82026-05-14
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project …
- CVE-2025-25061MEDIUMCVSS 5.8EG 5.82025-04-04
Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack.
- CVE-2026-84616MEDIUMCVSS 5.5EG 5.52026-09-14
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app…
- CVE-2026-69531MEDIUMCVSS 5.5EG 5.52026-09-08
Unintended proxy or intermediary ('confused deputy') in Microsoft Windows Speech allows an authorized attacker to perform tampering locally.
- CVE-2025-36889MEDIUMCVSS 5.5EG 5.52025-12-11
In onCreateTasks of CameraActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp…
- CVE-2025-32317MEDIUMCVSS 5.5EG 5.52025-09-05
In App Widget, there is a possible Information Disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2025-48560MEDIUMCVSS 5.5EG 5.52025-09-04
In AndroidManifest.xml, there is a possible way for an app to monitor motion events due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2025-48529MEDIUMCVSS 5.5EG 5.52025-09-04
In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interacti…
- CVE-2023-21082MEDIUMCVSS 5.5EG 5.52023-04-19
In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privi…
- CVE-2022-39349MEDIUMCVSS 5.5EG 5.52022-10-25
The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `ShareLinkActivity.kt` to handle "share" intents coming from other components in the same device and convert them to tasks. …
- CVE-2026-106427MEDIUMCVSS 5.4EG 5.42026-10-06
Confused deputy in Mobile in Google Chrome on on iOS prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-41365MEDIUMCVSS 5.4EG 5.42026-04-28
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering r…
- CVE-2025-66415MEDIUMCVSS 5.4EG 5.42025-12-01
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for spe…
- CVE-2026-87453MEDIUMCVSS 5.3EG 5.32026-09-09
Confused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-84329MEDIUMCVSS 5.3EG 5.32026-09-01
Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severi…
- CVE-2026-6993MEDIUMCVSS 5.3EG 5.32026-04-25
A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux Fallback Handler. The manipulation results in unintended in…
- CVE-2025-61780MEDIUMCVSS 5.3EG 5.32025-10-10
Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers (such as N…
- CVE-2026-86115MEDIUMCVSS 5.0EG 5.02026-09-05
Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL v…
- CVE-2026-45003MEDIUMCVSS 5.0EG 5.02026-05-11
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setti…
- CVE-2026-44992MEDIUMCVSS 5.0EG 5.02026-05-11
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled ori…
- CVE-2025-68944MEDIUMCVSS 5.0EG 5.02025-12-26
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
- CVE-2025-48551MEDIUMCVSS 5.0EG 5.02025-09-04
In multiple locations, there is a possible leak of an image across the Android User isolation boundary due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interacti…
- CVE-2026-91742MEDIUMCVSS 4.8EG 4.82026-09-15
Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via crafted network traffic. (Chromium s…
- CVE-2026-106326MEDIUMCVSS 4.4EG 4.42026-10-06
Confused deputy in UI in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security severity: Medium)
- CVE-2026-0183MEDIUMCVSS 4.4EG 4.42026-09-15
In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
- CVE-2026-106359MEDIUMCVSS 4.3EG 4.32026-10-06
Confused deputy in DeviceBoundSessionCredentials in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-95361MEDIUMCVSS 4.3EG 4.32026-09-29
Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-9595MEDIUMCVSS 4.3EG 4.32026-06-15
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin he…
- CVE-2026-30225MEDIUMCVSS 4.3EG 4.32026-03-06
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they ar…
- CVE-2024-9870MEDIUMCVSS 4.3EG 4.32025-02-12
An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.
- CVE-2015-10003MEDIUMCVSS 4.3EG 4.32022-07-17
A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the…
- CVE-2026-87502MEDIUMCVSS 4.2EG 4.22026-09-09
Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security seve…
- CVE-2026-47122MEDIUMCVSS 4.2EG 4.22026-05-29
Sparkle is a software update framework for macOS. In versions up to and including 2.9.1, `Autoupdate/AppInstaller.m`'s `shouldAcceptNewConnection:` only enforces `SUCodeSigningVerifier validateConnection:` before stage 1 completes. After `…
- CVE-2026-48522MEDIUMCVSS 4.2EG 4.22026-05-28
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandl…
- CVE-2018-1999038MEDIUMCVSS 4.2EG 4.22018-08-01
A confused deputy vulnerability exists in Jenkins Publisher Over CIFS Plugin 0.10 and earlier in CifsPublisherPluginDescriptor.java that allows attackers to have Jenkins connect to an attacker specified CIFS server with attacker specified …
- CVE-2025-48710MEDIUMCVSS 4.1EG 4.12025-06-04
kro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to supply arbitrary container images. This can lead to a confused-deputy scenario where kro's controll…
- CVE-2020-8561MEDIUMCVSS 4.1EG 4.12021-09-20
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiser…
- CVE-2026-106487LOWCVSS 3.5EG 3.52026-10-06
Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catal…
- CVE-2026-45519LOWCVSS 3.3EG 3.32026-09-08
In screenArgsForPermissionCheckIfAny of multiple locations there is a possible risk of unauthorized access due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User inter…
- CVE-2026-87442LOWCVSS 3.1EG 3.12026-09-09
Confused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2021-25740LOWCVSS 3.1EG 3.12021-09-20
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.
- CVE-2026-45723LOWCVSS 2.7EG 2.72026-06-05
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient…
- CVE-2026-45182LOWCVSS 2.2EG 2.22026-05-09
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its beh…
Map vulnerabilities like CWE-441 to your infrastructure
EchelonGraph correlates every CVE — across CWE-441 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →