CWE-1385: Missing Origin Validation in WebSockets
The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.
34 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-24964 — Remote Code Execution when accessing a malicious website while Vitest API server is listening
- CVE-2024-48849 — Authentication and Authorization Issues
- CVE-2025-52882 — Claude Code IDE extensions allow websocket connections from arbitrary origins
- CVE-2026-44211 — Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
- CVE-2026-85183 — Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS
- CVE-2025-54289 — Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API
- CVE-2026-10054 — In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc
- CVE-2025-61987 — GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5
- CVE-2026-35589 — nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update)
- CVE-2026-22689 — Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
- CVE-2025-24010 — Vite allows any websites to send any requests to the development server and read the response
- CVE-2026-59950 — MCP Python SDK: WebSocket server transport does not support Host/Origin validation
- CVE-2026-59804 — Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
- CVE-2025-36116 — IBM Db2 Mirror for i cross-site websocket hijacking
- CVE-2026-57111 — Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
- CVE-2026-15580 — PassPortal browser extension: vault token disclosure via unvalidated postMessage
- CVE-2026-44514 — Kubetail: Cross-Site WebSocket Hijacking allows attacker to read Kubernetes logs from authenticated users
- CVE-2026-1692 — Missing origin validation in GraphicalData web service requests
- CVE-2026-34403 — Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
- CVE-2026-21883 — Bokeh server applications have Incomplete Origin Validation in WebSockets
Recently published
- CVE-2026-85183 — Taipy through 4.1.1 Cross-Site WebSocket Hijacking via Wildcard socket.io CORS
- CVE-2026-15580 — PassPortal browser extension: vault token disclosure via unvalidated postMessage
- CVE-2026-59950 — MCP Python SDK: WebSocket server transport does not support Host/Origin validation
- CVE-2026-57111 — Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin
- CVE-2026-59804 — Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket
- CVE-2026-10054 — In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc
- CVE-2026-44211 — Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
- CVE-2026-44514 — Kubetail: Cross-Site WebSocket Hijacking allows attacker to read Kubernetes logs from authenticated users
- CVE-2026-34403 — Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints
- CVE-2026-35589 — nanobot: Cross-Site WebSocket Hijacking in WhatsApp Bridge (CVE-2026-2577 Fix Update)
- CVE-2026-27977 — Next.js: null origin can bypass dev HMR websocket CSRF checks
- CVE-2026-1692 — Missing origin validation in GraphicalData web service requests
- CVE-2026-22689 — Mailpit is vulnerable to Cross-Site WebSocket Hijacking (CSWSH) allowing unauthenticated access to emails
- CVE-2026-21883 — Bokeh server applications have Incomplete Origin Validation in WebSockets
- CVE-2025-61987 — GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupSession ZION prior to ver5
- CVE-2025-54289 — Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API
- CVE-2024-51775 — Apache Zeppelin: Command Injection via CSWSH
- CVE-2025-36116 — IBM Db2 Mirror for i cross-site websocket hijacking
- CVE-2025-52882 — Claude Code IDE extensions allow websocket connections from arbitrary origins
- CVE-2025-48068 — Information exposure in Next.js dev server due to lack of origin verification