๐Ÿ” CVE Alert

CVE-2026-90486

MEDIUM 6.3

openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgery

CVSS Score
6.3
EPSS Score
0.2%
EPSS Percentile
14th

A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.

CWE CWE-918
Vendor openstatushq
Product openstatus
Published Sep 12, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for openstatushq openstatus

Be the first to know when new medium vulnerabilities affecting openstatushq openstatus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

openstatusHQ / openstatus
f04c827112f30a11d571ebdad3892826034d6265

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403074 vuldb.com: https://vuldb.com/vuln/403074/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90486 vuldb.com: https://vuldb.com/submit/888087 github.com: https://github.com/openstatusHQ/openstatus/pull/2551 github.com: https://github.com/openstatusHQ/openstatus/commit/86f370c9c20074c3c3fdec53a359874b8e670fd4 github.com: https://github.com/openstatusHQ/openstatus/

Credits

๐Ÿ” erickfernandox (VulDB User) VulDB CNA Team