Vulnerability in Decidim Framework Allows Unvalidated Push Endpoint Subscriptions
CVE-2026-45573
6.4MEDIUM
What is CVE-2026-45573?
The Decidim participatory democracy framework contains an input validation vulnerability involving the notification subscription flow. When VAPID delivery is enabled, the system does not validate client-supplied push endpoints against an approved push service. Consequently, this flaw allows authenticated users to make server-side requests to arbitrary HTTPS endpoints, potentially leading to unauthorized access or actions within the affected environment. This issue has been resolved in subsequent versions including 0.30.9, 0.31.5, and 0.32.0.rc2.
Affected Version(s)
decidim < 0.30.9 < 0.30.9
decidim >= 0.31.0.rc1, < 0.31.5 < 0.31.0.rc1, 0.31.5
decidim >= 0.32.0.rc1, < 0.32.0 < 0.32.0.rc1, 0.32.0
