Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page. | |
| Title | DNS rebinding vulnerability in rojo serve HTTP API | |
| Weaknesses | CWE-350 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: redhat-cnalr
Published:
Updated: 2026-09-25T16:39:44.958Z
Reserved: 2026-09-25T08:47:33.471Z
Link: CVE-2026-97875
No data.
Status : Received
Published: 2026-09-25T11:17:16.470
Modified: 2026-09-25T17:17:21.657
Link: CVE-2026-97875
No data.
OpenCVE Enrichment
No data.