CVE-2021-33604
URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.
Scoring
- Severity
- LOW
- CVSS base score
- 2.5
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS probability
- 0.05%
- CWE
- CWE-172
- Published
- 2021-06-24
- Last modified
- 2026-03-13
Affected products
- Vaadin Vaadin
- Vaadin Vaadin
- Vaadin Vaadin
- Vaadin flow-server
- Vaadin flow-server
- Vaadin flow-server
Weakness type
Related vulnerabilities
- CVE-2026-48784 — Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
- CVE-2026-42926 — NGINX ngx_http_proxy_v2_module vulnerability
- CVE-2025-27110 — Libmodsecurity3 has possible bypass of encoded HTML entities
- CVE-2024-48909 — SpiceDB calls to LookupResources using LookupResources2 with caveats may return context is missing when it is not
- CVE-2019-12677 — Cisco Adaptive Security Appliance Software SSL VPN Denial of Service Vulnerability
- CVE-2019-10153 — A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in...
- CVE-2019-10160 — A security regression of CVE-2019-9636 was discovered in python since commit...