
Real example: CVE-2026-89058 | CVSS 7.4 (HIGH) Composite Score: 29.6/100 (MONITOR) No public exploit. Low EPSS. The math tells you what the severity label cannot: this is not urgent right now.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, resulting in a loss of confidentiality.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

Real example: CVE-2026-89058 | CVSS 7.4 (HIGH) Composite Score: 29.6/100 (MONITOR) No public exploit. Low EPSS. The math tells you what the severity label cannot: this is not urgent right now.