UNKNOWNhex

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection

CVE-2026-43972Published 1 month agoUpdated 2 days agoSource: OSV

Affected packages

  • gun

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.21%
EPSS percentile
12.0%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 12%.

gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection | HackTribune