CVE-2026-90486
Last modified
CVE-2026-90486 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts.
Description
A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| openstatusHQ | openstatus | f04c827112f30a11d571ebdad3892826034d6265 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-90486?
How severe is CVE-2026-90486?
How do I fix CVE-2026-90486?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9047Improper handling of factor key state in the multi-factor au…7.6
- CVE-2026-90472msgpack-java through 0.9.12 contains a stack overflow vulner…5.3
- CVE-2026-90473msgpack-java through 0.9.12 contains an integer overflow vul…5.3
- CVE-2026-90474MCPHub before 1.0.32 contains an authentication bypass vulne…6.8
- CVE-2026-9048The Slider Revolution plugin for WordPress is vulnerable to …4.3
- CVE-2026-90485A flaw has been found in IOBit Uninstaller 15.5.0.11. Affect…5.5
- CVE-2026-90487A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Af…4.3
- CVE-2026-90488A vulnerability was determined in Xuxueli xxl-job up to 3.4.…6.3
- CVE-2026-90489A vulnerability was identified in Xuxueli xxl-job up to 3.5.…3.5
- CVE-2026-90490A security flaw has been discovered in lenve vhr 1.0-SNAPSHO…6.3
- CVE-2026-90491A weakness has been identified in sanjevirau gsubs up to 1.0…6.3
- CVE-2026-90492A security vulnerability has been detected in webgjc web_rob…6.3
Are you affected by CVE-2026-90486?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
