Decolua · 9Router · CVE-2026-10269
**Name of the Vulnerable Software and Affected Versions**
decolua 9router versions prior to 0.4.1
**Description**
Improper authorization occurs in the HTTP Header Handler component due to the manipulation of the `Host` argument within the `isAuthenticated()` function located in the src/dashboardGuard.js file. This issue allows for remote exploitation.
**Recommendations**
Update to version 0.4.1.