HTTP Call Vulnerability in Frappe Web Application Framework
CVE-2026-31878

5MEDIUM

Key Information:

Vendor

Frappe

Status
Vendor
CVE Published:
11 March 2026

What is CVE-2026-31878?

Frappe, a popular full-stack web application framework, contains a vulnerability that allows an attacker to send specially crafted requests to specific endpoints. This can result in the server being tricked into making HTTP requests to an arbitrary service specified by the attacker. The issue is resolved in versions 14.100.1, 15.100.0, and 16.6.0, underscoring the importance of upgrading to the latest version to mitigate potential security threats associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

frappe >= 16.0.0, < 16.6.0 < 16.0.0, 16.6.0

frappe >= 15.0.0, < 15.100.0 < 15.0.0, 15.100.0

frappe < 14.100.1 < 14.100.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.