Threats Tagged 'cve-2026-55087'
View all threats tagged with 'cve-2026-55087'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-55087'
Click on any threat for detailed analysis and mitigation recommendations
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header (CVE-2026-55087)CVE-2026-55087 0 A vulnerability in ep_etherpad-lite versions 2.1.0 through 3.0.0 allows an attacker to exploit the x-proxy-path HTTP header. This header is unsafely reflected into admin HTML/JS/CSS assets, enabling cache-poisoning cross-site scripting (XSS) attacks. Additionally, in version 3.0.0, the x-proxy-path header can be used to craft an open redirect via a protocol-relative URL in the timeslider redirect handler. Both issues require the x-proxy-path header to reach the server, which is typically mitigated by properly configured reverse proxies. The vulnerability has a CVSS v3.1 base score of 6.1 (Medium). A fix is available in ep_etherpad-lite version 3.1.0 and later. Join the discussion | GCVE Database | 08/13/2026, 13:46:07 UTC Added: 08/13/2026, 17:48:33 UTC |
Showing 1 to 1 of 1 result