/
DirectorySecurity AdvisoriesPricing
Sign In
Security Advisories

CVE-2023-26114

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-26114

Severity

Unknown

Description

Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.

References

  • https://images.chainguard.dev/security/CGA-pphx-23w3-5m8g

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs