Cross-Origin WebSocket Exposure in Punk Versions by LNATION
CVE-2026-104380
Currently unrated
What is CVE-2026-104380?
The Punk product versions from 0.48 to 0.54 expose a critical WebSocket vulnerability by allowing Extended CONNECT requests to be processed without proper Origin checks. This flaw facilitates a cross-origin attack wherein an attacker can open a WebSocket connection to arbitrary paths and deduce responses based on whether those paths result in a 2xx success status. Such exploitation can lead to unauthorized access and manipulation of data through any reachable API route. To mitigate this risk, it is essential to update to Punk version 0.55 or later, which addresses this vulnerability.
