Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Niccolo Parlanti

#44170of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2026-40911
6.1
2026-05-14
Podinfo · Podinfo · CVE-2026-43644
**Name of the Vulnerable Software and Affected Versions** podinfo versions prior to 6.11.3 **Description** A reflected cross-site scripting issue exists in the '/echo' and '/api/echo' endpoints. The `echoHandler` function writes request body content directly to the response without setting explicit 'Content-Type' or 'X-Content-Type-Options' headers. This allows attackers to use cross-origin HTML pages with auto-submitting forms containing script payloads in the request body. Because of Go's content type detection, these responses are served as 'text/html', enabling the script to execute within the podinfo origin context when a victim visits the malicious page. **Recommendations** Update to a version later than 6.11.2. As a temporary workaround, restrict access to the '/echo' and '/api/echo' endpoints to minimize the risk of exploitation.