CVE Feed

    Dashboard / CVE / CVE-2026-34206

    CVE-2026-34206

    Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepted a client-supplied destination value and rendered it into HTML using Go's text/template. Because text/template does not perform contextual HTML escaping, an attacker could supply a crafted destination value that breaks out of the hidden input attribute and injects arbitrary script into the challenge page. This issue has been patched in version 1.12.2.

    Published:Mar 31, 2026
    Last Modified:Apr 8, 2026
    EPS:Mar 31, 2026
    EPSS Score:0.00038
    CVSS Score:6.1

    Affected Products

    Vendor
    Libops
    Product
    Captcha-protect
    Vendor
    Libops
    Product
    Captcha Protect

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High