HTTP Call Vulnerability in Frappe Web Application Framework
CVE-2026-31878
What is CVE-2026-31878?
Frappe, a popular full-stack web application framework, contains a vulnerability that allows an attacker to send specially crafted requests to specific endpoints. This can result in the server being tricked into making HTTP requests to an arbitrary service specified by the attacker. The issue is resolved in versions 14.100.1, 15.100.0, and 16.6.0, underscoring the importance of upgrading to the latest version to mitigate potential security threats associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
frappe >= 16.0.0, < 16.6.0 < 16.0.0, 16.6.0
frappe >= 15.0.0, < 15.100.0 < 15.0.0, 15.100.0
frappe < 14.100.1 < 14.100.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
