{"id":"CVE-2026-25155","aliases":["GHSA-vm6g-8r4h-22x8"],"url":"https://o3.security/vulnerability/CVE-2026-25155","summary":"[qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)","details":"Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.","published":"2026-02-03T21:12:13.235Z","modified":"2026-08-12T03:51:40.582813387Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@builder.io/qwik-city","fixedVersion":"1.12.0"}],"fix":{"url":"https://github.com/QwikDev/qwik/commit/d70d7099b90b998f1aac7cedc21c67d87bac4c75","label":"QwikDev/qwik@d70d709"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25155.json"},{"type":"ADVISORY","url":"https://github.com/QwikDev/qwik/security/advisories/GHSA-vm6g-8r4h-22x8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25155"},{"type":"FIX","url":"https://github.com/QwikDev/qwik/commit/d70d7099b90b998f1aac7cedc21c67d87bac4c75"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.582813387Z"}}