PT-2026-48729 · Codexbar · Codexbar
CVE-2026-49949
·
Published
2026-06-11
·
Updated
2026-06-11
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodexBar versions prior to 0.33.0
Description
A credential forwarding issue allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared
ProviderHTTPClient transport. This enables the redirection of credentialed provider requests containing browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture the information.Recommendations
Update to version 0.33.0 or later.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codexbar