CWE-1385Variant

Missing Origin Validation in WebSockets

Incomplete in the CWE catalog · 34 CVEs mapped

34
CVEs mapped
7.0
Median CVSS
What it is

The product uses a WebSocket, but it does not properly verify that the source of data or communication is valid.

Recent examples
9.3cvss
CVE-2026-85183

CVE-2026-85183 - CRITICAL Severity Vulnerability

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection.

CRITICALno explanation yet
0%
epss
none
CVE-2026-15580

CVE-2026-15580 - UNKNOWN Severity Vulnerability

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6.

no explanation yet
0%
epss
7.6cvss
CVE-2026-59950

MCP Python SDK: WebSocket server transport does not support Host/Origin validation

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1385
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (5)