Improper sanitization of the `status` query parameter of...
High severity
Unreviewed
Published
May 14, 2026
to the GitHub Advisory Database
•
Updated May 14, 2026
Description
Published by the National Vulnerability Database
May 13, 2026
Published to the GitHub Advisory Database
May 14, 2026
Last updated
May 14, 2026
Improper sanitization of the
statusquery parameter of the/unprotected/nova_errorendpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.References