CWE-350 · 28 kayıt
Reliance on Reverse DNS Resolution for a Security-Critical Action
Bu sınıftaki CVE’ler
28 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-22884İstismar yok | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”.nodejs · node.js · CWE-350 | Yüksek7,5 | — | %32,4 | 3 Mar 2021 |
39İzleyin | CVE-2026-1490İstismar yok | Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Instacleantalk · spam protection, honeypot, anti-spam by cleantalk · CWE-350 | Kritik9,8 | — | %1,2 | 15 Şub 2026 |
38İzleyin | CVE-2018-7160İstismar yok | The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution.nodejs · node.js · CWE-350 | Yüksek8,8 | — | %9,9 | 17 May 2018 |
38İzleyin | CVE-2026-61568İstismar yok | @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transportzereight · gitlab-mcp · CWE-350 | Kritik9,6 | — | %0,5 | 15 Eyl 2026 |
35İzleyin | CVE-2021-34561İstismar yok | A vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebindingpepperl-fuchs · wha-gw-f2d2-0-as-z2-eth firmware · CWE-350 | Yüksek8,8 | — | %0,9 | 31 Ağu 2021 |
35İzleyin | CVE-2023-52235Kavram kanıtı | SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reCWE-350 | Yüksek8,8 | — | %0,5 | 5 Nis 2024 |
34İzleyin | CVE-2026-56709İstismar yok | Grav before 3.9.2 Host Header Injection via sendInvitationEmailgetgrav · grav · CWE-350 | Yüksek8,7 | — | %0,4 | 24 Ağu 2026 |
34İzleyin | CVE-2026-55526İstismar yok | PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)mervinpraison · praisonai · CWE-350 | Yüksek8,5 | — | %0,4 | 25 Ağu 2026 |
33İzleyin | CVE-2017-0902İstismar yok | RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client rubygems · rubygems · CWE-350 | Yüksek8,1 | — | %4,7 | 31 Ağu 2017 |
32İzleyin | CVE-2025-8036İstismar yok | DNS rebinding circumvents CORSmozilla · firefox · CWE-350 | Yüksek8,1 | — | %0,4 | 22 Tem 2025 |
32İzleyin | CVE-2026-97875İstismar yok | DNS rebinding vulnerability in rojo serve HTTP APIrojo-rbx · rojo · CWE-350 | Yüksek8,1 | — | %0,3 | 5 gün önce |
30İzleyin | CVE-2026-33002İstismar yok | Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made tjenkins · jenkins · CWE-350 | Yüksek7,5 | — | %0,4 | 18 Mar 2026 |
30İzleyin | CVE-2026-55391İstismar yok | datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebindingkoxudaxi · datamodel-code-generator · CWE-350 | Yüksek7,5 | — | %0,3 | 28 Tem 2026 |
26İzleyin | CVE-2026-28271İstismar yok | Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)accellion · kiteworks · CWE-350 | Orta6,5 | — | %0,5 | 27 Şub 2026 |
26İzleyin | CVE-2025-59956İstismar yok | AgentAPI exposed user chat history via a DNS rebinding attackcoder · agentapi · CWE-350 | Orta6,5 | — | %0,4 | 30 Eyl 2025 |
26İzleyin | CVE-2026-36604İstismar yok | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks.CWE-350 | Orta6,5 | — | %0,4 | 3 Haz 2026 |
26İzleyin | CVE-2026-53708İstismar yok | ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)ibm · mcp-context-forge · CWE-350 | Orta6,6 | — | %0,4 | 14 Eyl 2026 |
26İzleyin | CVE-2024-42364İstismar yok | homepage DNS rebinding vulnerability (GHSL-2024-096)gethomepage · homepage · CWE-350 | Orta6,5 | — | %0,3 | 23 Ağu 2024 |
26İzleyin | CVE-2025-61430İstismar yok | Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server CWE-350 | Orta6,5 | — | %0,3 | 24 Eki 2025 |
25İzleyin | CVE-2026-61743İstismar yok | Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validationchartbrew · chartbrew · CWE-350 | Orta6,3 | — | %0,4 | 21 Eyl 2026 |
23İzleyin | CVE-2020-11091İstismar yok | Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisementsweave · weave net · CWE-350 | Orta5,8 | — | %0,9 | 3 Haz 2020 |
23İzleyin | CVE-2026-75514İstismar yok | BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibotbunkerity · bunkerweb · CWE-350 | Orta5,9 | — | %0,6 | 20 Ağu 2026 |
22İzleyin | CVE-2023-32020İstismar yok | Windows DNS Spoofing Vulnerabilitymicrosoft · windows server 2008 · CWE-350 | Orta5,6 | — | %0,7 | 13 Haz 2023 |
21İzleyin | CVE-2022-22364İstismar yok | IBM Cognos Controller security bypassibm · cognos controller · CWE-350 | Orta5,3 | — | %0,5 | 3 May 2024 |
21İzleyin | CVE-2024-53275İstismar yok | GHSL-2024-091: DNS rebinding attack in home-galleryxemle · home-gallery · CWE-350 | Orta5,3 | — | %0,3 | 23 Ara 2024 |
- CVE-2021-2288440Planlayın
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”.
YüksekCVSS 7,5İstismar yokEPSS %32nodejs · node.js3 Mar 2021
- CVE-2026-149039İzleyin
Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Insta
KritikCVSS 9,8İstismar yokEPSS %1cleantalk · spam protection, honeypot, anti-spam by cleantalk15 Şub 2026
- CVE-2018-716038İzleyin
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution.
YüksekCVSS 8,8İstismar yokEPSS %10nodejs · node.js17 May 2018
- CVE-2026-6156838İzleyin
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
KritikCVSS 9,6İstismar yokEPSS %1zereight · gitlab-mcp15 Eyl 2026
- CVE-2021-3456135İzleyin
A vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebinding
YüksekCVSS 8,8İstismar yokEPSS %1pepperl-fuchs · wha-gw-f2d2-0-as-z2-eth firmware31 Ağu 2021
- CVE-2023-5223535İzleyin
SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a re
YüksekCVSS 8,8Kavram kanıtıEPSS %15 Nis 2024
- CVE-2026-5670934İzleyin
Grav before 3.9.2 Host Header Injection via sendInvitationEmail
YüksekCVSS 8,7İstismar yokEPSS %0getgrav · grav24 Ağu 2026
- CVE-2026-5552634İzleyin
PraisonAI: SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
YüksekCVSS 8,5İstismar yokEPSS %0mervinpraison · praisonai25 Ağu 2026
- CVE-2017-090233İzleyin
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client
YüksekCVSS 8,1İstismar yokEPSS %5rubygems · rubygems31 Ağu 2017
- CVE-2025-803632İzleyin
DNS rebinding circumvents CORS
YüksekCVSS 8,1İstismar yokEPSS %0mozilla · firefox22 Tem 2025
- CVE-2026-9787532İzleyin
DNS rebinding vulnerability in rojo serve HTTP API
YüksekCVSS 8,1İstismar yokEPSS %0rojo-rbx · rojo5 gün önce
- CVE-2026-3300230İzleyin
Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made t
YüksekCVSS 7,5İstismar yokEPSS %0jenkins · jenkins18 Mar 2026
- CVE-2026-5539130İzleyin
datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding
YüksekCVSS 7,5İstismar yokEPSS %0koxudaxi · datamodel-code-generator28 Tem 2026
- CVE-2026-2827126İzleyin
Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)
OrtaCVSS 6,5İstismar yokEPSS %1accellion · kiteworks27 Şub 2026
- CVE-2025-5995626İzleyin
AgentAPI exposed user chat history via a DNS rebinding attack
OrtaCVSS 6,5İstismar yokEPSS %0coder · agentapi30 Eyl 2025
- CVE-2026-3660426İzleyin
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks.
OrtaCVSS 6,5İstismar yokEPSS %03 Haz 2026
- CVE-2026-5370826İzleyin
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)
OrtaCVSS 6,6İstismar yokEPSS %0ibm · mcp-context-forge14 Eyl 2026
- CVE-2024-4236426İzleyin
homepage DNS rebinding vulnerability (GHSL-2024-096)
OrtaCVSS 6,5İstismar yokEPSS %0gethomepage · homepage23 Ağu 2024
- CVE-2025-6143026İzleyin
Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server to cause the server
OrtaCVSS 6,5İstismar yokEPSS %024 Eki 2025
- CVE-2026-6174325İzleyin
Chartbrew: DNS Rebinding SSRF Bypass in Outbound Request Validation
OrtaCVSS 6,3İstismar yokEPSS %0chartbrew · chartbrew21 Eyl 2026
- CVE-2020-1109123İzleyin
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
OrtaCVSS 5,8İstismar yokEPSS %1weave · weave net3 Haz 2020
- CVE-2026-7551423İzleyin
BunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibot
OrtaCVSS 5,9İstismar yokEPSS %1bunkerity · bunkerweb20 Ağu 2026
- CVE-2023-3202022İzleyin
Windows DNS Spoofing Vulnerability
OrtaCVSS 5,6İstismar yokEPSS %1microsoft · windows server 200813 Haz 2023
- CVE-2022-2236421İzleyin
IBM Cognos Controller security bypass
OrtaCVSS 5,3İstismar yokEPSS %1ibm · cognos controller3 May 2024
- CVE-2024-5327521İzleyin
GHSL-2024-091: DNS rebinding attack in home-gallery
OrtaCVSS 5,3İstismar yokEPSS %0xemle · home-gallery23 Ara 2024