Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-2026-25155'

View all threats tagged with 'cve-2026-25155'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-25155

Threats Tagged 'cve-2026-25155'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-25155: CWE-352: Cross-Site Request Forgery (CSRF) in QwikDev qwikCVE-2026-25155
0

CVE-2026-25155 is a medium severity Cross-Site Request Forgery (CSRF) vulnerability in the Qwik JavaScript framework versions prior to 1.12.0. The flaw stems from a typo in the regular expression used by the isContentType function, causing improper parsing of certain Content-Type headers. This parsing error can be exploited by attackers to craft malicious requests that bypass normal CSRF protections, potentially leading to unauthorized actions with high integrity impact but low confidentiality and no availability impact. The vulnerability requires user interaction and remote network access but no authentication. Although no known exploits are reported in the wild, organizations using vulnerable Qwik versions should upgrade to 1.12.0 or later. European organizations that heavily rely on Qwik for web applications, especially in countries with significant software development ecosystems, are at risk.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: cve-2026-25155
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses