CWE-346: Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
304 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-34291 — Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
- CVE-2026-54069 — SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
- CVE-2025-9265 — API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
- CVE-2024-32764 — myQNAPcloud Link
- CVE-2025-69258 — A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta
- CVE-2026-22794 — Account Takeover Vulnerability in Appsmith
- CVE-2025-59159 — SillyTavern Web Interface Vulnerable to DNS Rebinding
- CVE-2025-3651 — Command Injection in iManage Work Desktop for Mac's Agent Service
- CVE-2025-25306 — Misskey's Incomplete Patch of CVE-2024-52591 Leads to Forgery of Federated Notes
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2024-32642 — Host header poisoning allows account takeover via password reset email
- CVE-2025-25302 — Rembg CORS misconfiguration
- CVE-2026-20893 — Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If
- CVE-2025-3462 — "This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insuffici
- CVE-2024-26135 — MeshCentral cross-site websocket hijacking (CSWSH) vulnerability
- CVE-2025-59845 — Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
- CVE-2025-23023 — Anonymous cache poisoning via request headers in Discourse
- CVE-2026-6508 — RCE in TUBITAK BILGEM's Liderahenk
- CVE-2026-44649 — SillyTavern: Authentication Bypass via SSO Header Injection
- CVE-2023-49899 — Origin Validation Error in X-Rite MA-T6
Recently published
- CVE-2026-87563 — Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origi
- CVE-2026-75156 — Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
- CVE-2026-85152 — undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors
- CVE-2026-84482 — WWBN AVideo Cross-Site Request Forgery via get_domain() validation
- CVE-2026-82811 — Toggl OÜ Toggl Track Extension postMessage origin validation
- CVE-2026-81315 — MCP DNS-rebinding origin check in AshAi is bypassed by a spoofed X-Forwarded-Proto header
- CVE-2026-81102 — Dropbox Dash MCP Server DNS Rebinding via Missing Host Header Validation
- CVE-2026-81100 — Timescale tiger-gh-mcp-server DNS Rebinding via Disabled Host Header Allow-List
- CVE-2026-81099 — Timescale tiger-slack DNS Rebinding via Disabled Host Header Allow-List
- CVE-2026-81095 — Timescale pg-aiguide through 0.5.0 DNS Rebinding via Disabled Host Header Allow-List
- CVE-2026-81092 — mcp-go before 0.56.0 Missing Host Header Validation Enables DNS Rebinding
- CVE-2026-55637 — genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
- CVE-2026-55532 — PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
- CVE-2026-55529 — PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows browser-mediated unauthenticated tool execution on local MCP server
- CVE-2026-72702 — Grav CMS before 2.0.16 Origin Validation Bypass via Referer
- CVE-2026-53499 — FORT-validator Vulnerable to RRDP Shared Snapshot Cache Poisoning
- CVE-2026-53656 — FiftyOne App server uses wildcard CORS (Access-Control-Allow-Origin: *), enabling cross-origin reads of local server data
- CVE-2026-62316 — Microsoft UFO: DNS Rebinding → Unauthenticated File Read / Command Execution
- CVE-2026-67448 — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-22689)
- CVE-2026-74802 — SiYuan 3.7.3 Cross-Site WebSocket Hijacking via network proxy
More specific weaknesses
- CWE-1385 — Missing Origin Validation in WebSockets