Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response. | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2026-05-13T22:06:04.114Z
Reserved: 2026-03-17T15:00:07.746Z
Link: CVE-2026-32993
No data.
Status : Received
Published: 2026-05-13T22:16:43.143
Modified: 2026-05-13T22:16:43.143
Link: CVE-2026-32993
No data.
OpenCVE Enrichment
Updated: 2026-05-13T23:30:06Z
Weaknesses