CVE-2026-93682

LOWCVSS 5.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-28: 209-28
Full discourse2 posts
  • Mayur Rawale@RawaleMayur

    Hi @Plesk VAPT identified vulnerabilities in PHP 8.2.x, 8.3.x, 8.4.x and 8.5.x (CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682). What is the recommended mitigation/update procedure for Plesk

    000005
    323 followersView on X
  • Mayur Rawale@RawaleMayur

    Hi @cPanel , VAPT identified vulnerabilities in PHP 8.2.x, 8.3.x, 8.4.x and 8.5.x (CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682). What is the recommended cPanel/EasyApache 4 mitigation or update procedure?

    000005
    323 followersView on X

Explore more