CVE-2026-21826
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Hos
CVSS
6.1
Medium
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Jun 5, 2026 · Last modified: Jul 23, 2026 · CWE-601
0.1%EPSS · 30 days0.1%
2026-08-062026-09-02
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected ways.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-846624.3 MED—
——0Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified URL through Stapler data binding, allowing attackers to connect to an attacker-specified URL.1dCVE-2026-737345.4 MED14.1%
——4A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to redirect users to an arbitrary URL.2dCVE-2026-82731—20.9%
——6URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, and the credentials attached to it, to an unintended route or an external origin.
The URL builders in lib/ash_typescript/typed_controller/codegen/route_renderer.ex replace each :param placeholder with a bare template interpolation and never call encodeURIComponent, so the value reaches executeTypedControllerRequest raw. A value containing ../ is normalised away by the fetch URL resolver and reaches a different route, while ? or # truncates the path and can smuggle or override query parameters. For a route whose path begins with a parameter, a value such as /evil.example.com/x yields the protocol-relative URL //evil.example.com/x, sending the request and the credentials from TypedControllerConfig to an attacker-controlled host. Nothing constrains the value at runtime: get_path_param_type/2 emits only a TypeScript type, which is erased.
The query-string path is unaffected, since URLSearchParams.set encodes its own values.
This issue affects ash_typescript: from 0.15.0 before 0.18.0.2dCVE-2026-78079—17.7%
——5Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted arbitrary Base64 strings without verifying whether the resolved target was an internal site URL via Uri::isInternal.4dCVE-2026-404655.3 MED7.0%
——2NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.4dCVE-2026-824674.7 MED8.7%
——3Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation.3d