Vulnerability in Decidim Framework Allows Unvalidated Push Endpoint Subscriptions
CVE-2026-45573

6.4MEDIUM

Key Information:

Vendor

Decidim

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-45573?

The Decidim participatory democracy framework contains an input validation vulnerability involving the notification subscription flow. When VAPID delivery is enabled, the system does not validate client-supplied push endpoints against an approved push service. Consequently, this flaw allows authenticated users to make server-side requests to arbitrary HTTPS endpoints, potentially leading to unauthorized access or actions within the affected environment. This issue has been resolved in subsequent versions including 0.30.9, 0.31.5, and 0.32.0.rc2.

Affected Version(s)

decidim < 0.30.9 < 0.30.9

decidim >= 0.31.0.rc1, < 0.31.5 < 0.31.0.rc1, 0.31.5

decidim >= 0.32.0.rc1, < 0.32.0 < 0.32.0.rc1, 0.32.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.