CWE-940: Improper Verification of Source of a Communication Channel
The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
45 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-61932 — Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of
- CVE-2025-59159 — SillyTavern Web Interface Vulnerable to DNS Rebinding
- CVE-2026-33875 — Authenticator Vulnerable to Authentication Flow Hijack
- CVE-2025-40820 — Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within
- CVE-2019-25613 — Easy Chat Server 3.1 Denial of Service via message Parameter
- CVE-2025-23222 — An issue was discovered in Deepin dde-api-proxy through 1.0.19 in which unprivileged users can access D-Bus services as
- CVE-2024-26131 — Element Android Intent Redirection
- CVE-2024-1621 — uniFLOW Online device registration susceptible to compromise
- CVE-2024-49579 — In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized
- CVE-2026-85085 — The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who
- CVE-2026-48745 — Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
- CVE-2026-45353 — electerm: Local code through electerm's single-instance socket
- CVE-2025-9999 — Improper validation of payload elements
- CVE-2026-35643 — OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
- CVE-2026-78685 — Le-yan|Medical Practice Management System - Remote Code Execution
- CVE-2025-25305 — SSL validation for outgoing requests in Home Assistant Core and used libs not correct
- CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
- CVE-2026-40434 — Anviz CrossChex Standard Improper Verification of Source of a Communication Channel
- CVE-2026-55660 — TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
- CVE-2026-2967 — Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source
Recently published
- CVE-2026-85085 — The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who
- CVE-2026-78685 — Le-yan|Medical Practice Management System - Remote Code Execution
- CVE-2026-73419 — NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
- CVE-2026-55660 — TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
- CVE-2026-54106 — U.S. GAO EPDS and CBCA EDS network access control bypass
- CVE-2026-48745 — Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
- CVE-2026-44894 — Netty's Default QUIC token handler accepts any client-supplied token
- CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
- CVE-2026-45353 — electerm: Local code through electerm's single-instance socket
- CVE-2026-45245 — Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events
- CVE-2026-43880 — WWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address
- CVE-2026-40434 — Anviz CrossChex Standard Improper Verification of Source of a Communication Channel
- CVE-2026-35643 — OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
- CVE-2026-33875 — Authenticator Vulnerable to Authentication Flow Hijack
- CVE-2019-25613 — Easy Chat Server 3.1 Denial of Service via message Parameter
- CVE-2026-2967 — Cesanta Mongoose TCP Sequence Number net_builtin.c getpeer verification of source
- CVE-2025-62439 — An Improper Verification of Source of a Communication Channel vulnerability [CWE-940] vulnerability in Fortinet FortiOS
- CVE-2025-40820 — Affected products do not properly enforce TCP sequence number validation in specific scenarios but accept values within
- CVE-2025-13086 — Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows
- CVE-2025-61932 — Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of
More specific weaknesses
- CWE-925 — Improper Verification of Intent by Broadcast Receiver