CVE-2026-93682

CVE-2026-93682 published: When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte decides which redirec...

View full NVD advisory → ← Back to CVE watch