CVE-2026-50285

CVE-2026-50285 published: Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V2 values for Statele...

View full NVD advisory → ← Back to CVE watch