Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9r33-xhw8-4qqp | HAX CMS: Denial of Service using Malicious Import Request |
Tue, 09 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Haxtheweb
Haxtheweb haxcms-nodejs |
|
| Vendors & Products |
Haxtheweb
Haxtheweb haxcms-nodejs |
Fri, 05 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service. Version 26.0.0 fixes the issue. | |
| Title | HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Request | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-09T14:36:15.648Z
Reserved: 2026-05-13T18:37:30.991Z
Link: CVE-2026-46357
Updated: 2026-06-09T14:21:45.613Z
Status : Deferred
Published: 2026-06-05T20:17:33.190
Modified: 2026-06-09T16:16:41.843
Link: CVE-2026-46357
No data.
OpenCVE Enrichment
Updated: 2026-06-05T21:00:04Z
Github GHSA