CVE-2026-90486 | openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265 resolve-custom-domain-rewrite.ts server-side request forgery (ID 2551)
A vulnerability classified as critical has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-90486. The attack may be initiated remotely. There is no available exploit.
This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. It is suggested to install a patch to address this issue.
This issue got fixed with a silent patch.VulDB Recent EntriesRead More