CVE-2026-104380
Last modified
CVE-2026-104380 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Punk versions from 0.48 before 0.55 for Perl route Extended CONNECT requests to any GET route without an Origin check in ps_serve_one. On HTTP/2 and HTTP/3 a WebSocket handshake arrives as an Extended CONNECT, which is matched as a GET and so reaches every GET route, API operation and mount. The Origin check runs only when a websocket route matches. On this transport the handler's status is the handshake response, and a 2xx accepts it. A cross-origin page can open a WebSocket to any path and learn from its open or error event whether that path returns 2xx.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | >= 0.48, < 0.55 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104380?
How severe is CVE-2026-104380?
How do I fix CVE-2026-104380?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104286An improper limitation of a pathname to a restricted directo…9.8
- CVE-2026-1043The PostmarkApp Email Integrator plugin for WordPress is vul…4.4
- CVE-2026-104313The WPC Estimated Delivery Date for WooCommerce plugin for W…6.1
- CVE-2026-104334IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote a…9.8
- CVE-2026-104335IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote a…8.8
- CVE-2026-104356PictShare before version 3.7.1 contains a weak randomness vu…5.9
- CVE-2026-104385Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8…7.5
- CVE-2026-104386Missing Authorization vulnerability in WPFunnels Team WP VR …6.5
- CVE-2026-104387Unauthenticated Broken Access Control in PowerPress Podcasti…7.2
- CVE-2026-104388Missing Authorization vulnerability in Blubrry Podcasting Po…5.3
- CVE-2026-104389Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2026-104390Missing Authorization vulnerability in Arraytics Booktics bo…4.3
Are you affected by CVE-2026-104380?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
