Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hw27-4v2q-5qff | Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * |
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xyproto
Xyproto algernon |
|
| Vendors & Products |
Xyproto
Xyproto algernon |
Tue, 26 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Origin response header was hardcoded to the wildcard * regardless of the caller's Origin. Because EventSource does not preflight and does not send cookies, the wildcard is sufficient to let any third-party page the developer visits open a cross-origin EventSource to the SSE port and read the live filename stream from JavaScript. This vulnerability is fixed in 1.17.7. | |
| Title | Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * | |
| Weaknesses | CWE-942 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-26T17:39:14.529Z
Reserved: 2026-05-13T22:18:22.830Z
Link: CVE-2026-46431
Updated: 2026-05-26T17:39:03.913Z
Status : Deferred
Published: 2026-05-26T17:16:51.100
Modified: 2026-06-17T10:53:40.107
Link: CVE-2026-46431
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:04:42Z
Github GHSA