Threats Tagged 'cve-2026-41691'
View all threats tagged with 'cve-2026-41691'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-41691'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-41691 is a path traversal and URL injection vulnerability in i18next-http-backend versions prior to 3.0.5. The issue arises because the library interpolates language (lng) and namespace (ns) values directly into URL templates without encoding or sanitization. This allows an attacker controlling these inputs to manipulate the request URL structure, potentially accessing restricted paths. The vulnerability has been fixed in version 3.0.5. Until upgrading, users can mitigate risk by sanitizing lng and ns inputs to remove dangerous characters and limit length. Join the discussion | CVE Database V5 | 05/07/2026, 20:09:24 UTC Added: 05/07/2026, 20:36:23 UTC |
Showing 1 to 1 of 1 result