Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tvrinssen

#30151of 57,355
9.1Total CVSS
Vulnerabilities · 1
PT-2026-96056
9.1
2026-09-21
Openvsx · Openvsx · CVE-2025-12999
**Name of the Vulnerable Software and Affected Versions** Open VSX (affected versions not specified) **Description** An unauthenticated remote attacker can poison the per-extension metadata cache by supplying crafted `X-Forwarded-Host`, `X-Forwarded-Proto`, and `X-Forwarded-Prefix` request headers. The `UrlUtil.getBaseUrl()` function builds absolute URLs for download links, icons, assets, and API URLs using these headers without verifying if the sender is a trusted proxy. Because responses are cached using keys that do not include the host, a single forged request can inject attacker-controlled URLs into entries served to all other clients. This allows an attacker to supply a malicious VSIX package along with its own signature and public key, leading VS Code-compatible editors to install malicious software. This issue affects servers reachable directly by clients or those behind proxies that relay rather than overwrite these headers. **Recommendations** Configure the reverse proxy to set instead of relay the `X-Forwarded-Host`, `X-Forwarded-Proto`, and `X-Forwarded-Prefix` headers. Ensure the server is only reachable through the configured proxy. Flush the caches after applying configuration changes to remove poisoned entries.