CVE-2026-46611: Xmlrpc Server Dns Rebinding
The request handler overrides `parse_request` but does not validate the HTTP `Host` header. Without checking the `Host` header before processing requests or authenticating clients, the server is vulnerable to DNS rebinding attacks if it is bound to localhost or an internal network. Attackers can extract data or call APIs from the local server via a victim's
greprules fetch cve-2026-46611-xmlrpc-server-dns-rebinding --engine opengrepDescription
The request handler overrides `parse_request` but does not validate the HTTP `Host` header. Without checking the `Host` header before processing requests or authenticating clients, the server is vulnerable to DNS rebinding attacks if it is bound to localhost or an internal network. Attackers can extract data or call APIs from the local server via a victim's
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.