CVE-2026-32993 UNKNOWN

CVE-2026-32993

Published: 2026-05-13

Description

Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…