Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Host Header Injection in Shynet Password Reset Flow |
Fri, 10 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shynet
Shynet shynet |
|
| CPEs | cpe:2.3:a:shynet:shynet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Shynet
Shynet shynet |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Host Header Injection in Shynet Password Reset Flow | |
| First Time appeared |
Milesmcc
Milesmcc shynet |
|
| Vendors & Products |
Milesmcc
Milesmcc shynet |
Fri, 03 Apr 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shynet before 0.14.0 allows Host header injection in the password reset flow. | |
| Weaknesses | CWE-348 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T13:21:46.817Z
Reserved: 2026-04-03T01:00:34.056Z
Link: CVE-2026-35507
Updated: 2026-04-03T13:21:43.691Z
Status : Analyzed
Published: 2026-04-03T02:16:15.170
Modified: 2026-04-10T02:01:43.630
Link: CVE-2026-35507
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:45:40Z