CVE-2026-27971Disclosure(qwik / qwik)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch qwik qwik systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qwik

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • Disclosure: 8 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 4 mentions (2026-03-04); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
qwik

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-03-03: 2Mentions · 2026-03-04: 4Mentions · 2026-03-05: 1Mentions · 2026-03-09: 2Mentions · 2026-03-10: 1Mentions · 2026-03-25: 1Active Exploitation · 2026-03-25: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 4Technical Details · 2026-03-05: 1Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-25: 103-0303-0403-0503-0903-1003-25
Signal classification4 categories
Disclosure
872.7%
Patch
19.1%
General
19.1%
Active Exploitation
19.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-032
Disclosure2
2026-03-044
Disclosure3Patch1
2026-03-051
Disclosure1
2026-03-092
Disclosure2
2026-03-101
General1
2026-03-251
Active Exploitation1
Full discourse11 posts
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-27971: Critical RCE Flaw in Qwik Framework Allows Server Takeover via Single Request 📊 46K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Qwik%22 👇Query HUNTER : http://product.name="Qwik" 📰Refer:https://securityonline.info/critical-rce-flaw-in-qwik-framework-allows-server-takeover-via-single-request/ https://github.com/QwikDev/qwik/security/advisories/GHSA-p9x5-jp3h-96mm #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The message announces a newly discovered critical RCE vulnerability (CVE-2026-27971) in the Qwik Framework, offering a link to an advisory but no PoC, exploit tool, or patch details.

    01102292.8K
    25.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27971 - critical 🚨 Qwik - Unauthenticated RCE via server$ Deserialization &gt; Qwik &lt;=1.19.0 contains an insecure deserialization vulnerability in the server$ RPC m... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27971 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical vulnerability, CVE-2026-27971, has been disclosed in Qwik (versions ≤1.19.0) caused by insecure deserialization of server$ RPC data, enabling unauthenticated remote code execution.

    13019111.4K
    902 followersView on X
  • Clandestine@akaclandestine
    Disclosure

    Qwik - Unauthenticated RCE via server$ Deserialization https://cloud.projectdiscovery.io/library/CVE-2026-27971

    Post summary

    The data points to a newly disclosed vulnerability, CVE‑2026‑27971, that allows unauthenticated remote code execution in Qwik via server$ deserialization, with details hosted on a public library page.

    01043837
    55.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Qwik framework patches a critical 9.2 CVSS RCE vulnerability (CVE-2026-27971) where unsafe deserialization in server$ RPC allows total server takeover. #Qwik #CyberSecurity #RCE #CVE202627971 #WebDev #InfoSec #Vulnerability #JavaScript #AppSec #TechNews https://securityonline.info/critical-rce-flaw-in-qwik-framework-allows-server-takeover-via-single-request/

    Post summary

    The Qwik framework has released a patch for CVE-2026-27971, a critical RCE vulnerability caused by unsafe deserialization in server$ RPC, with a CVSS score of 9.2.

    20010260
    10.5K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『Affects any deployment where require() is available at runtime.』 CVE-2026-27971 Unauthenticated RCE via server$ Deserialization · Advisory · QwikDev/qwik · GitHub https://github.com/QwikDev/qwik/security/advisories/GHSA-p9x5-jp3h-96mm

    Post summary

    CVE-2026-27971 is an unauthenticated remote code execution flaw caused by server‑side deserialization in QwikDev/qwik, affecting any deployment that uses Node’s require() at runtime.

    00011463
    6.7K followersView on X
  • Divert@Divert_Security
    Active Exploitation

    CVE-2026-27971, Qwik unsafe deserialization --&gt; code execution was disclosed 3/3/2026. Divert caught and blocked probes starting 3/9/2026. The same threat was then caught trying to exploit CVE-2026-27944, an Nginx UI key disclosure on 3/6/2026, the day after its disclosure. https://t.co/iO47yzPLAg

    Post summary

    The tweet reports that probing and attempted exploitation of CVE-2026-27971 and CVE-2026-27944 were detected and blocked, indicating active exploitation activity.

    0001068
    7 followersView on X
  • VulnTracker@vuln_tracker
    General

    CVE-2026-27971 in Qwik shows even modern JS frameworks aren't immune to classic deserialization bugs. Unauthenticated RCE via server$ is exactly why we need tools like Nuclei to catch these patterns. Thanks for the detection template. Track and monitor this CVE: https://vulntracker.io/cves/CVE-2026-27971

    Post summary

    The text announces CVE-2026-27971 as an unauthenticated RCE in Qwik via a classic deserialization bug, but provides no PoC, exploit code, or patch details.

    0000071
    394 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27971 Remote Code Execution in Qwik Framework Server$ RPC Mechanism Before 1.19.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27971

    Post summary

    A new RCE vulnerability (CVE-2026-27971) affecting Qwik Framework's Server$ RPC mechanism before version 1.19.1 has been disclosed, but no PoC, exploit, or patch details are provided.

    0000080
    4.0K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Modern JS frameworks aren't immune to classic vulnerabilities. CVE-2026-27971 shows how unsafe deserialization can still lead to full server compromise - even in performance-focused frameworks like Qwik. CVSS 9.2 reflects the severity: unauthenticated RCE via single request. http://vulntracker.io/cves/CVE-2026-27971

    Post summary

    The post discloses CVE-2026-27971, detailing unsafe deserialization that allows unauthenticated RCE with a CVSS score of 9.2, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000074
    381 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27971 Qwik is a performance focused javascript framework. qwik &lt;=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism tha… https://www.cve.org/CVERecord?id=CVE-2026-27971 ----- Traducción: CVE-2026-27971 Qwi… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27971, noting that Qwik versions <=1.19.0 are vulnerable to RCE via unsafe deserialization in its server RPC mechanism, but provides no PoC, exploit, or patch information.

    0000055
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27971 Qwik is a performance focused javascript framework. qwik &lt;=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism tha… https://www.cve.org/CVERecord?id=CVE-2026-27971

    Post summary

    The post discloses that Qwik versions up to 1.19.0 are vulnerable to remote code execution due to unsafe deserialization in the server$ RPC mechanism.

    00000235
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqwikqwik-node.js-

Explore more