tag
Spoofing
CVE-2026-4893
network
MEDIUM
dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)
This PoC demonstrates that dnsmasq, when configured with EDNS Client Subnet (ECS, RFC 7871) via add-subnet, will accept an upstream DNS response carrying an ECS option whose subnet does not match the subnet dnsmasq originally sent in the query. The included…
Patched
2026-07-05
None assigned as of 2026-07-03
web
HIGH
NodeBB ActivityPub attributedTo Local UID Spoof
NodeBB's ActivityPub inbox authenticates the top-level signed actor of an incoming activity via HTTP Signatures, but never checks that the embedded Note.attributedTo field — used later as the internal local user id for chat message and post authorship —…
Unverified
2026-07-03