Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
http4k-core versions before 6.49.0.0, 5.42.0.0, and 4.51.0.0 use substring matching on the Host header in reverseProxy() and reverseProxyRouting() functions. This behavior can allow an attacker to bypass routing-based authorization by supplying a Host header that contains a configured virtual host name as a substring. This issue affects public-facing inbound HTTP handlers with multiple configured virtual hosts. The vulnerability does not affect outbound dispatch or test-time uses where the Host header is set by the application. Join the discussion | GCVE Database | 09/27/2026, 03:31:03 UTC Added: 09/27/2026, 04:29:54 UTC |
http4k-core versions before 6.48.0.0, 5.42.0.0, and 4.51.0.0 include a BasicCookieStorage implementation that does not properly enforce RFC 6265 cookie scoping rules. This flaw allows cookies intended for one origin or scheme to be sent to others, and Secure cookies may be transmitted over unencrypted HTTP connections. Clients using BasicCookieStorage for multiple origins or schemes are affected, while those using it for a single origin are not. Join the discussion | GCVE Database | 09/27/2026, 03:31:03 UTC Added: 09/27/2026, 04:29:54 UTC |
Showing 1 to 2 of 2 results