CVE Feed

    Dashboard / CVE / CVE-2026-43644

    CVE-2026-43644

    podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the response without setting explicit Content-Type or X-Content-Type-Options headers. Attackers can craft cross-origin HTML pages with auto-submitting forms containing script payloads in the request body, which are served as text/html due to Go's content type detection, allowing the reflected script to execute in the podinfo origin context when victims visit the attacker's page.

    Published:May 14, 2026
    Last Modified:Jun 1, 2026
    EPS:May 14, 2026
    EPSS Score:0.00031
    CVSS Score:5.4

    Affected Products

    Vendor
    Stefanprodan
    Product
    Podinfo

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High