HIGHVulnerability
CVE-2026-82639
NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any URL containing 'api.openai.com' to pass validation and receive the server's credentials in the Authorization header.
Properties
- severity
- HIGH
- score
- 7.5
- epss_score
- 0.00298
- cve_id
- CVE-2026-82639
- signal_observed_at
- 2026-09-15T21:12:48+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- published_at
- 2026-08-30T14:17:03.750
- last_modified
- 2026-09-10T15:53:23.707
- epss_percentile
- 0.22412
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Improper Input Validation
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph