← Back

Uncurl

uncurl

Vendor: Uncurl Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Parsecgaming
Uncurl Project
2Parsec
Uncurl
Jun 17, 2026
Feb 5, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote...Show more
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.Show less