PT-2026-38639 · Unknown · App Router
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
App Router applications (affected versions not specified)
Description
Stored cross-site scripting is possible in applications relying on Content Security Policy (CSP) nonces when deployed behind shared caches. Malformed nonce values derived from request headers can be reflected into rendered HTML unsafely, enabling an attacker to poison cached responses and execute scripts for subsequent visitors. CSP nonces are security tokens used to allow only specific inline scripts to execute, preventing unauthorized script injection.
Recommendations
Update the software to a version where malformed nonce values are rejected or ignored and stricter sanitization is applied.
Strip inbound
Content-Security-Policy request headers from untrusted traffic as a temporary workaround.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
App Router