Missing Origin Validation in WebSockets Affecting github.com/kubetail-org/kubetail/modules/dashboard package, versions <0.14.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMKUBETAILORGKUBETAILMODULESDASHBOARD-17086950
  • published29 May 2026
  • disclosed7 May 2026
  • creditUnknown

Introduced: 7 May 2026

CVE-2026-44514  (opens in a new tab)
CWE-1385  (opens in a new tab)

How to fix?

Upgrade github.com/kubetail-org/kubetail/modules/dashboard to version 0.14.0 or higher.

Overview

Affected versions of this package are vulnerable to Missing Origin Validation in WebSockets via inadequate validation of the Origin header during WebSocket connection upgrades. An attacker can gain unauthorized access to sensitive log data by convincing an authenticated user to visit a malicious web page, which then establishes a WebSocket connection to the user's dashboard and streams Kubernetes logs accessible to the victim. This is only exploitable if the victim has an active authenticated session and visits an attacker-controlled page in the same browser, and the attacker knows or can guess the dashboard URL.

CVSS Base Scores

version 4.0
version 3.1