By weakness (CWE)
CWE-644: related vulnerabilities
CVEs classified under CWE-644. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
1 published vulnerability
- CVE-2026-4096MEDIUM 6.5
IBM DevOps Plan versions 3.0.0 through 3.0.6 contain a flaw in how they validate HTTP HOST headers, allowing attackers to inject malicious header content. This could lead to several attack vectors including stealing user session data, poisoning cached content, or executing code in users' browsers through cross-site scripting (XSS). The vulnerability requires network access but no authentication or user interaction to exploit.