6.4
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Description
Shynet before 0.14.0 allows Host header injection in the password reset flow.
Basic Information
ID
CVE-2026-35507
Source
mitre
Published
Apr 3, 2026 at 01:00
Modified
Apr 3, 2026 at 13:21
Affected Product
Vendor
milesmcc
Product
Shynet
Affected Versions
milesmcc Shynet 0