PT-2026-38639 · Unknown · App Router

·

CVE-2026-44581

·

Published

2026-05-06

·

Updated

2026-08-17

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions App Router applications (affected versions not specified)
Description Stored cross-site scripting is possible in applications relying on Content Security Policy (CSP) nonces when deployed behind shared caches. Malformed nonce values derived from request headers can be reflected into rendered HTML unsafely, enabling an attacker to poison cached responses and execute scripts for subsequent visitors. CSP nonces are security tokens used to allow only specific inline scripts to execute, preventing unauthorized script injection.
Recommendations Update the software to a version where malformed nonce values are rejected or ignored and stricter sanitization is applied. Strip inbound Content-Security-Policy request headers from untrusted traffic as a temporary workaround.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07001
CVE-2026-44581
GHSA-FFHC-5MCF-PF4Q

Affected Products

App Router