Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 25 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rojo's "rojo serve" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page. | |
| Title | DNS rebinding vulnerability in rojo serve HTTP API | |
| Weaknesses | CWE-350 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat-cnalr
Published:
Updated: 2026-09-25T16:39:44.958Z
Reserved: 2026-09-25T08:47:33.471Z
Link: CVE-2026-97875
No data.
Status : Received
Published: 2026-09-25T11:17:16.470
Modified: 2026-09-25T11:17:16.470
Link: CVE-2026-97875
No data.
OpenCVE Enrichment
No data.
Weaknesses