7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Description
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
Basic Information
ID
CVE-2026-43510
Source
cisa-cg
Published
May 7, 2026 at 18:50
Affected Product
Vendor
CISA
Product
manage.get.gov
Affected Versions
CISA manage.get.gov 0
CWE Classification
References
- github.com /cisagov/manage.get.gov/pull/4900
- github.com /cisagov/manage.get.gov/releases/tag/v1.176.0
- github.com /cisagov/manage.get.gov/security/advisories/GHSA-6wrg-x3j6-x464
- www.cve.org /CVERecord
- raw.githubusercontent.com /cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json
- github.com /cisagov/manage.get.gov/issues/4858