HTTP Plugin Vulnerability in Tauri Framework
CVE-2026-95623
5.6MEDIUM
What is CVE-2026-95623?
The Tauri HTTP plugin has a flaw that allows malicious redirects to unapproved destinations. It performs URL validation against a configured allowlist only at the initial request. When an HTTP 3xx redirect occurs, the system does not re-validate the new target URL, enabling an attacker to leverage an allowed URL to direct traffic to restricted or harmful endpoints. This can compromise internal services or sensitive data retrieval points, posing significant risks to affected applications.
Affected Version(s)
tauri-plugin-http 2.0.0 <= 2.6.1
tauri-plugin-http 2.7.0
References
CVSS V3.1
Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yuval Moravchick
JFrog Security Research
