CVE-2026-59891: Insecure Dict Key Substring Match

Using a substring match to find a dictionary key can lead to insecure matching (e.g., when checking hostnames, URLs or registry names), allowing an attacker to spoof configurations by registering a similar name (like an overlapping substring). Prefer exact matches (`===`) or proper parsing.

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0JS
greprules fetch cve-2026-59891-insecure-dict-key-substring-match --engine opengrep

Description

Using a substring match to find a dictionary key can lead to insecure matching (e.g., when checking hostnames, URLs or registry names), allowing an attacker to spoof configurations by registering a similar name (like an overlapping substring). Prefer exact matches (`===`) or proper parsing.