CVE-2026-10836
Improper neutralization of HTTP headers in Password Manager
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using specially crafted requests. A successful exploit could result in the generation of manipulated links or responses, potentially leading to limited information disclosure or compromising the integrity of dependent services.
| CWE | CWE-644 |
| Vendor | password manager |
| Product | password manager |
| Published | Jun 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for password manager password manager
Be the first to know when new unknown vulnerabilities affecting password manager password manager are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Password Manager / Password Manager
0 < 08/07/2025