Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jg68-vhv3-9r8f | Magento's X-Original-Url header can expose admin url |
Fri, 20 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:openmage:magento:*:*:*:*:lts:*:*:* |
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openmage
Openmage magento |
|
| Vendors & Products |
Openmage
Openmage magento |
Wed, 04 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1. | |
| Title | Magento's X-Original-Url header can expose admin url | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-04T21:40:35.514Z
Reserved: 2026-02-02T18:21:42.487Z
Link: CVE-2026-25523
Updated: 2026-02-04T21:38:07.271Z
Status : Analyzed
Published: 2026-02-04T22:15:59.353
Modified: 2026-02-20T20:57:08.667
Link: CVE-2026-25523
No data.
OpenCVE Enrichment
Updated: 2026-04-17T23:15:30Z
Github GHSA