CVE-2026-82291 | HeyForm 3.0.0-rc.7 CORS Origin cross-domain policy
A vulnerability, which was classified as problematic, was found in HeyForm 3.0.0-rc.7. This vulnerability affects unknown code of the component CORS. Executing a manipulation of the argument Origin can lead to permissive cross-domain policy with untrusted domains.
This vulnerability is handled as CVE-2026-82291. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More