CWE-942

CWE-942 · 3 records · 2 with a public proof-of-concept

Records the NVD classes under CWE-942, highest CVSS first.

  1. LOW 3.1CVE-2026-92359public PoC

    A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipulation results in permi…

    AI risk analysis on Exploit-DB.ai →

  2. UNSCOREDCVE-2026-66070public PoC

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin…

    AI risk analysis on Exploit-DB.ai →

  3. UNSCOREDCVE-2026-90882

    The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue credentialed requests to th…

    AI risk analysis on Exploit-DB.ai →