Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Peter Hassall

#30206de 53,638
8.7CVSS total
Vulnerabilidades · 1
PT-2026-22060
8.7
2026-02-26
Unknown · Terriajs-Server · CVE-2026-27818
**Name of the Vulnerable Software and Affected Versions** TerriaJS-Server versions prior to 4.0.3 **Description** A validation flaw permits an attacker to proxy domains not explicitly listed in the `proxyableDomains` configuration. The validation process only verifies if a hostname ends with an allowed domain, which allows malicious domains to be proxied through the server. For example, if `example.com` is in `proxyableDomains`, `maliciousexample.com` could also be proxied. This bypasses proxy restrictions. **Recommendations** Upgrade to version 4.0.3 to resolve the issue.