EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to correlated intelligence
Vulnerability

CVE-2026-93682

Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.

Sharing
PUBLIC-OSINT
Confidence
100
Source
The CVE Program
Updated
26/09/2026 02:59

Description

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirect target is built, so a malicious server controls whether the client is sent to the host root or to the current directory.

STIX identifiervulnerability--eee01b65-9fa4-5987-a9f6-fbd6babd66d4
First observation-
Last observation-
Known relationships8

Aliases and classifications

CWE-125Out-of-bounds Read

Minimised technical details

No raw data
cisa kev
False
cvss score
5.8
cvss vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
cvss severity
MEDIUM
EudorIA correlation

Intel catalogue

The vulnerability is also available in the EudorIA editorial catalogue.

Open EudorIA analysis

Presence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.