Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 18 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Server‑Side Request Forgery via XSS Filter Misconfiguration |
Fri, 23 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:naver:lucy-xss-filter:*:*:*:*:*:*:*:* |
Fri, 16 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Naver
Naver lucy-xss-filter |
|
| Vendors & Products |
Naver
Naver lucy-xss-filter |
Fri, 16 Jan 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListener or EmbedSecurityListener option is enabled and embed or object tags are used with a src attribute missing a file extension. | |
| Weaknesses | CWE-918 | |
| References |
|
Status: PUBLISHED
Assigner: naver
Published:
Updated: 2026-01-16T16:01:19.373Z
Reserved: 2026-01-16T05:06:27.869Z
Link: CVE-2026-23768
Updated: 2026-01-16T16:01:01.135Z
Status : Analyzed
Published: 2026-01-16T06:15:51.333
Modified: 2026-01-23T17:26:59.110
Link: CVE-2026-23768
No data.
OpenCVE Enrichment
Updated: 2026-04-18T19:15:10Z