CVE-2026-46391 affects the HAX CMS-related package @haxtheweb/open-apis from version 9.0.1 up to, but not including, 26.0.0. Multiple functions use substring-only hostname validation to decide whether outbound requests should include basic authorization credentials. Because the validation checks only whether a trusted hostname substring appears in the destination rather than enforcing exact hostname matching, an attacker can supply or influence a crafted attacker-controlled endpoint whose hostname contains the trusted substring. The application may then send basic authorization credentials to the attacker-controlled host. The issue is described as enabling credential capture through server-side request behavior and is fixed in version 26.0.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact Go proof-of-concept exploit for CVE-2026-46391 affecting @haxtheweb/open-apis. It is not part of a larger exploit framework. The repo contains 7 files total: one main exploit source file (main.go), one substantial Go test file (main_test.go), a README, Go module metadata, license, gitignore, and a GitHub Actions workflow. The exploit’s purpose is credential exposure via SSRF. It targets the vulnerable cacheAddress API endpoint at /api/services/website/cacheAddress by sending a GET request with a crafted q parameter. That q parameter is built as an attacker-controlled callback URL ending in /.aanda.psu.edu, which is explicitly intended to satisfy a substring check in the vulnerable application. After triggering the SSRF, the tool runs a local HTTP listener and waits for the target server to connect back. When the callback arrives on the crafted path, the exploit inspects the Authorization header, attempts to decode Basic authentication credentials, and prints the recovered service-account credentials. Main capabilities in main.go: - Parses CLI arguments for target URL, listener host, listener port, timeout, and verbose logging. - Starts an HTTP listener on the operator’s machine. - Builds a callback URL from a bare IP/hostname or full HTTP/HTTPS URL. - Sends the SSRF trigger request to the vulnerable endpoint. - Receives inbound callback requests and optionally logs headers/body. - Extracts and decodes Basic Authorization credentials from the callback. - Reports captured credentials or timeout/failure conditions. The exploit is operational rather than a bare detection script because it performs the full attack chain and captures secrets, but it is still a focused PoC rather than a highly modular weaponized framework. The included tests validate callback URL construction, auth decoding, listener behavior, and duplicate callback handling.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.