{"id":"CVE-2026-27818","aliases":["GHSA-w789-49fc-v8hr"],"url":"https://o3.security/vulnerability/CVE-2026-27818","summary":"TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist","details":"TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A validation bug in versions prior to 4.0.3 allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration. Version 4.0.3 fixes the issue.","published":"2026-02-26T00:02:45.127Z","modified":"2026-08-12T03:51:21.405307094Z","cvss":null,"epss":{"score":0.00241,"percentile":0.14986,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"terriajs-server","fixedVersion":"4.0.3"}],"fix":{"url":"https://github.com/TerriaJS/terriajs-server/commit/3aaa5d9717162b245ae4569232bbe7d8673c913f","label":"TerriaJS/terriajs-server@3aaa5d9"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27818.json"},{"type":"ADVISORY","url":"https://github.com/TerriaJS/terriajs-server/security/advisories/GHSA-w789-49fc-v8hr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27818"},{"type":"FIX","url":"https://github.com/TerriaJS/terriajs-server/commit/3aaa5d9717162b245ae4569232bbe7d8673c913f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.405307094Z"}}