CVE-2026-55087 | ether Etherpad up to 3.0.x Proxy Header admin.ts x-proxy-path redirect

SecurityVulns

A vulnerability marked as problematic has been reported in ether Etherpad up to 3.0.x. Affected by this vulnerability is an unknown functionality of the file src/node/hooks/express/admin.ts of the component Proxy Header Handler. Performing a manipulation of the argument x-proxy-path results in open redirect.

This vulnerability is reported as CVE-2026-55087. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More