Common Weakness Enumeration

CWE-923

Allowed-with-Review

Improper Restriction of Communication Channel to Intended Endpoints

Abstraction: Class · Status: Incomplete

The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

140 vulnerabilities reference this CWE, most recent first.

GHSA-VC7R-JRPG-M6J5

Vulnerability from github – Published: 2026-03-10 18:31 – Updated: 2026-03-10 18:31
VLAI
Details

A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions < F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions < L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-27769"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-03-10T18:17:52Z",
    "severity": "LOW"
  },
  "details": "A vulnerability has been identified in Heliox Flex 180 kW EV Charging Station (All versions \u003c F4.11.1), Heliox Mobile DC 40 kW EV Charging Station (All versions \u003c L4.10.1). Affected devices contain improper access control that could allow an attacker to reach unauthorized services via the charging cable.",
  "id": "GHSA-vc7r-jrpg-m6j5",
  "modified": "2026-03-10T18:31:18Z",
  "published": "2026-03-10T18:31:18Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27769"
    },
    {
      "type": "WEB",
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-126399.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-VP9H-P637-9XFW

Vulnerability from github – Published: 2024-05-03 15:30 – Updated: 2024-08-01 15:31
VLAI
Details

Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-34446"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-05-03T15:15:08Z",
    "severity": "HIGH"
  },
  "details": "Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.",
  "id": "GHSA-vp9h-p637-9xfw",
  "modified": "2024-08-01T15:31:43Z",
  "published": "2024-05-03T15:30:55Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34446"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mullvad/mullvadvpn-app/commit/0c39306a40f426853d617e20d596942e41091f13"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mullvad/mullvadvpn-app/blob/main/CHANGELOG.md"
    },
    {
      "type": "WEB",
      "url": "https://github.com/mullvad/mullvadvpn-app/tags"
    },
    {
      "type": "WEB",
      "url": "https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android"
    },
    {
      "type": "WEB",
      "url": "https://news.ycombinator.com/item?id=40247604"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-W34Q-CM8F-9C5X

Vulnerability from github – Published: 2026-09-17 20:31 – Updated: 2026-09-17 20:31
VLAI
Summary
OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning
Details

Summary

The OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry.

Introduced in commit: d99c76f

Details

The affected code is in exporters/otlp/otlplog/otlploggrpc.

newConfig resolves env-based TLS configuration into cfg.tlsCfg at exporters/otlp/otlplog/otlploggrpc/config.go:106-116. The finding also identifies loadEnvTLS at config.go:451-492 as the code that builds a *tls.Config containing RootCAs and client certificates from OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE and OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE/KEY.

However, newGRPCDialOptions in exporters/otlp/otlplog/otlploggrpc/client.go:83-92 only checks cfg.gRPCCredentials and cfg.insecure. When neither is set, which is the normal env-only TLS configuration path, it uses credentials.NewTLS(nil). That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other tlsCfg use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.

PoC

validation-artifact.zip

The validation artifact contains a ready-to-run test at validation-artifact.zip:./poc_env_tls_ignored_test.go and brief instructions at validation-artifact.zip:./README.md.

From a checkout of pellared/opentelemetry-go at commit d99c76f, with Go module dependencies available:

FINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning
cd /path/to/opentelemetry-go
git checkout d99c76f
tar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go > exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go
cd exporters/otlp/otlplog/otlploggrpc
GO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1

The test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:

OTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:<test-port>
OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=<temp-dir>/ca.pem

Expected output includes an unknown authority failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same cfg.tlsCfg is explicitly wired through WithTLSCredentials:

=== RUN   TestEnvTLSIgnored
    poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority
--- PASS: TestEnvTLSIgnored
PASS

This demonstrates that the env CA is parsed into cfg.tlsCfg but ignored by the default gRPC dial path.

Impact

This is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit WithTLSCredentials. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.21.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-81871"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-295",
      "CWE-923"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-17T20:31:09Z",
    "nvd_published_at": "2026-09-16T21:17:22Z",
    "severity": "MODERATE"
  },
  "details": "### Summary\n\nThe OTLP log gRPC exporter loads TLS settings from environment variables but does not apply them when creating gRPC transport credentials. Operators who rely on `OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE`, `OTEL_EXPORTER_OTLP_CERTIFICATE`, or related client certificate variables for CA pinning or mTLS get a connection that falls back to system roots and omits the env-supplied client certificate. A network attacker who can intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. \n\nIntroduced in commit: d99c76f\n\n### Details\n\nThe affected code is in `exporters/otlp/otlplog/otlploggrpc`.\n\n`newConfig` resolves env-based TLS configuration into `cfg.tlsCfg` at `exporters/otlp/otlplog/otlploggrpc/config.go:106-116`. The finding also identifies `loadEnvTLS` at `config.go:451-492` as the code that builds a `*tls.Config` containing `RootCAs` and client certificates from `OTEL_EXPORTER_OTLP[_LOGS]_CERTIFICATE` and `OTEL_EXPORTER_OTLP[_LOGS]_CLIENT_CERTIFICATE`/`KEY`.\n\nHowever, `newGRPCDialOptions` in `exporters/otlp/otlplog/otlploggrpc/client.go:83-92` only checks `cfg.gRPCCredentials` and `cfg.insecure`. When neither is set, which is the normal env-only TLS configuration path, it uses `credentials.NewTLS(nil)`. That default trusts the host system root CAs and contains no env-supplied client certificate. The finding evidence reports no other `tlsCfg` use in the package, so env-based CA pinning and mTLS settings are loaded but not enforced.\n\n### PoC\n\n[validation-artifact.zip](https://github.com/user-attachments/files/27493589/validation-artifact.zip)\n\n\nThe validation artifact contains a ready-to-run test at `validation-artifact.zip:./poc_env_tls_ignored_test.go` and brief instructions at `validation-artifact.zip:./README.md`.\n\nFrom a checkout of `pellared/opentelemetry-go` at commit `d99c76f`, with Go module dependencies available:\n\n```sh\nFINDING_DIR=/path/to/02-e6e2897a969c8191b260f243fbc99ebd-log-grpc-exporter-ignores-env-tls-certs-bypassing-mtls-pinning\ncd /path/to/opentelemetry-go\ngit checkout d99c76f\ntar -xOf validation-artifact.tar ./poc_env_tls_ignored_test.go \u003e exporters/otlp/otlplog/otlploggrpc/poc_env_tls_ignored_test.go\ncd exporters/otlp/otlplog/otlploggrpc\nGO111MODULE=on go test -v -run TestEnvTLSIgnored -count=1\n```\n\nThe test generates a private CA and a TLS gRPC logs server certificate signed by that CA. It sets:\n\n```sh\nOTEL_EXPORTER_OTLP_LOGS_ENDPOINT=https://127.0.0.1:\u003ctest-port\u003e\nOTEL_EXPORTER_OTLP_LOGS_CERTIFICATE=\u003ctemp-dir\u003e/ca.pem\n```\n\nExpected output includes an `unknown authority` failure for the first export call even though the env certificate points to the server CA, followed by a passing test after the same `cfg.tlsCfg` is explicitly wired through `WithTLSCredentials`:\n\n```text\n=== RUN   TestEnvTLSIgnored\n    poc_env_tls_ignored_test.go:...: export error (expected due to ignored tlsCfg): ... x509: certificate signed by unknown authority\n--- PASS: TestEnvTLSIgnored\nPASS\n```\n\nThis demonstrates that the env CA is parsed into `cfg.tlsCfg` but ignored by the default gRPC dial path.\n\n### Impact\n\nThis is improper TLS certificate validation and endpoint authentication caused by ignoring configured trust material. Users of the OTLP log gRPC exporter who configure TLS, CA pinning, or mTLS through environment variables are impacted when they do not also supply explicit `WithTLSCredentials`. TLS still occurs with system roots, but the intended private CA pinning and client certificate authentication are bypassed. An attacker with a suitable network position and a system-trusted certificate for the collector endpoint can intercept or tamper with log telemetry that operators expected to be protected by the configured CA or mTLS policy.",
  "id": "GHSA-w34q-cm8f-9c5x",
  "modified": "2026-09-17T20:31:09Z",
  "published": "2026-09-17T20:31:09Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81871"
    },
    {
      "type": "WEB",
      "url": "https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/open-telemetry/opentelemetry-go"
    },
    {
      "type": "WEB",
      "url": "https://github.com/open-telemetry/opentelemetry-go/releases/tag/exporters/otlp/otlplog/otlploggrpc/v0.21.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinning"
}

GHSA-W3GP-GPRX-5VJ8

Vulnerability from github – Published: 2024-09-26 18:31 – Updated: 2024-10-04 21:31
VLAI
Details

The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-47125"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-287",
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-09-26T18:15:09Z",
    "severity": "HIGH"
  },
  "details": "The goTenna Pro series does not authenticate public keys which allows an unauthenticated attacker to intercept and manipulate messages.",
  "id": "GHSA-w3gp-gprx-5vj8",
  "modified": "2024-10-04T21:31:28Z",
  "published": "2024-09-26T18:31:45Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47125"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-270-04"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-W762-77XF-823W

Vulnerability from github – Published: 2024-08-05 06:30 – Updated: 2024-08-07 21:31
VLAI
Details

Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-41889"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-08-05T05:15:39Z",
    "severity": "HIGH"
  },
  "details": "Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.",
  "id": "GHSA-w762-77xf-823w",
  "modified": "2024-08-07T21:31:43Z",
  "published": "2024-08-05T06:30:37Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41889"
    },
    {
      "type": "WEB",
      "url": "https://github.com/OpenMAR/PiTool"
    },
    {
      "type": "WEB",
      "url": "https://jvn.jp/en/jp/JVN50850706"
    },
    {
      "type": "WEB",
      "url": "https://pimax.com/pages/downloads-manuals"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WCVF-3X75-J4C6

Vulnerability from github – Published: 2026-06-23 06:30 – Updated: 2026-08-25 12:31
VLAI
Details

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-55655"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-06-23T04:17:40Z",
    "severity": "MODERATE"
  },
  "details": "A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.",
  "id": "GHSA-wcvf-3x75-j4c6",
  "modified": "2026-08-25T12:31:20Z",
  "published": "2026-06-23T06:30:41Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55655"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:36759"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:47755"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:47756"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:47757"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:54387"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/errata/RHSA-2026:58981"
    },
    {
      "type": "WEB",
      "url": "https://access.redhat.com/security/cve/CVE-2026-55655"
    },
    {
      "type": "WEB",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2462250"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-WH8R-HXHG-W5G2

Vulnerability from github – Published: 2023-06-23 18:30 – Updated: 2024-04-04 05:07
VLAI
Details

NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2023-25515"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-822",
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-06-23T18:15:10Z",
    "severity": "HIGH"
  },
  "details": "\nNVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity. \n\n",
  "id": "GHSA-wh8r-hxhg-w5g2",
  "modified": "2024-04-04T05:07:09Z",
  "published": "2023-06-23T18:30:23Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25515"
    },
    {
      "type": "WEB",
      "url": "https://https://nvidia.custhelp.com/app/answers/detail/a_id/5466"
    },
    {
      "type": "WEB",
      "url": "https://https://nvidia.custhelp.com/app/answers/detail/a_id/5468"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-X279-FQQW-2JVV

Vulnerability from github – Published: 2025-01-28 03:31 – Updated: 2025-01-28 03:31
VLAI
Details

IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-22315"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-01-28T02:15:28Z",
    "severity": "MODERATE"
  },
  "details": "IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.",
  "id": "GHSA-x279-fqqw-2jvv",
  "modified": "2025-01-28T03:31:14Z",
  "published": "2025-01-28T03:31:14Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22315"
    },
    {
      "type": "WEB",
      "url": "https://www.ibm.com/support/pages/node/7179168"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-X7QM-J22R-CGCW

Vulnerability from github – Published: 2026-09-30 21:32 – Updated: 2026-10-01 21:32
VLAI
Details

Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-92173"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-09-30T21:17:17Z",
    "severity": "CRITICAL"
  },
  "details": "Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.",
  "id": "GHSA-x7qm-j22r-cgcw",
  "modified": "2026-10-01T21:32:48Z",
  "published": "2026-09-30T21:32:13Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92173"
    },
    {
      "type": "WEB",
      "url": "https://www.facebook.com/security/advisories/cve-2026-92173"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-XC4G-8C26-VCMF

Vulnerability from github – Published: 2026-07-10 00:31 – Updated: 2026-07-10 00:31
VLAI
Details

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.

Due to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.

This issue affects Junos OS Evolved:

  • all versions before 23.2R2-S7-EVO,
  • 23.4 versions before 23.4R2-S8-EVO,
  • 24.2 versions before 24.2R2-S5-EVO,
  • 24.4 versions before 24.4R2-S4-EVO,
  • 25.2 versions before 25.2R2-S1-EVO,
  • 25.4 versions before 25.4R1-S2-EVO.
Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-33803"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-923"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-07-09T22:17:03Z",
    "severity": "MODERATE"
  },
  "details": "An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.\n\n\nDue to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.\n\nThis issue affects Junos OS Evolved:\n\n\n  *  all versions before 23.2R2-S7-EVO,\n  *  23.4 versions before 23.4R2-S8-EVO,\n  *  24.2 versions before 24.2R2-S5-EVO,\n  *  24.4 versions before 24.4R2-S4-EVO,\n  *  25.2 versions before 25.2R2-S1-EVO,\n  *  25.4 versions before 25.4R1-S2-EVO.",
  "id": "GHSA-xc4g-8c26-vcmf",
  "modified": "2026-07-10T00:31:25Z",
  "published": "2026-07-10T00:31:25Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33803"
    },
    {
      "type": "WEB",
      "url": "https://supportportal.juniper.net/JSA110078"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:X",
      "type": "CVSS_V4"
    }
  ]
}

No mitigation information available for this CWE.

CAPEC-161: Infrastructure Manipulation

An attacker exploits characteristics of the infrastructure of a network entity in order to perpetrate attacks or information gathering on network objects or effect a change in the ordinary information flow between network objects. Most often, this involves manipulation of the routing of network messages so, instead of arriving at their proper destination, they are directed towards an entity of the attackers' choosing, usually a server controlled by the attacker. The victim is often unaware that their messages are not being processed correctly. For example, a targeted client may believe they are connecting to their own bank but, in fact, be connecting to a Pharming site controlled by the attacker which then collects the user's login information in order to hijack the actual bank account.

CAPEC-481: Contradictory Destinations in Traffic Routing Schemes

Adversaries can provide contradictory destinations when sending messages. Traffic is routed in networks using the domain names in various headers available at different levels of the OSI model. In a Content Delivery Network (CDN) multiple domains might be available, and if there are contradictory domain names provided it is possible to route traffic to an inappropriate destination. The technique, called Domain Fronting, involves using different domain names in the SNI field of the TLS header and the Host field of the HTTP header. An alternative technique, called Domainless Fronting, is similar, but the SNI field is left blank.

CAPEC-501: Android Activity Hijack

An adversary intercepts an implicit intent sent to launch a Android-based trusted activity and instead launches a counterfeit activity in its place. The malicious activity is then used to mimic the trusted activity's user interface and prompt the target to enter sensitive data as if they were interacting with the trusted activity.

CAPEC-697: DHCP Spoofing

An adversary masquerades as a legitimate Dynamic Host Configuration Protocol (DHCP) server by spoofing DHCP traffic, with the goal of redirecting network traffic or denying service to DHCP.