{"id":"CVE-2026-97875","summary":"DNS rebinding vulnerability in rojo serve HTTP API","details":"Rojo's \"rojo serve\" HTTP API (default port 34872) has no Host/Origin header validation, making it vulnerable to DNS rebinding. A malicious webpage can read all project source, write malicious code to files on disk, and launch local programs via opener::open() with no user interaction beyond visiting the page.","aliases":["RUSTSEC-2026-0279"],"modified":"2026-09-27T03:47:39.304452551Z","published":"2026-09-25T10:48:47.726Z","database_specific":{"cna_assigner":"redhat-cnalr","cwe_ids":["CWE-350"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97875.json"},"references":[{"type":"WEB","url":"https://crates.io"},{"type":"WEB","url":"https://osv.dev/vulnerability/RUSTSEC-2026-0279"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97875.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97875"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0279.html"},{"type":"FIX","url":"https://github.com/rojo-rbx/rojo/pull/1270"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rojo-rbx/rojo","events":[{"introduced":"0"},{"fixed":"bcadc97de27ab3800e915abcb72c6c7a3c30f363"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"7.7.0"}]}}],"versions":["v7.7.0-rc.1","v7.6.1","v7.6.0","v7.5.1","v7.5.0","v7.4.0","v7.4.0-rc3","v7.4.0-rc2","v7.4.0-rc1","v7.3.0","v7.2.1-release-test-3","v7.2.1-static-openssl","v7.2.1","v7.2.0","v7.1.1","v7.1.0","v7.0.0","v7.0.0-rc.3","v7.0.0-rc.1","v7.0.0-alpha.4","v7.0.0-alpha.3","v6.0.2","v7.0.0-alpha.2","v7.0.0-alpha.1","v6.0.1","v6.0.0","v6.0.0-rc.4","v6.0.0-rc.3","v6.0.0-rc.2","v6.0.0-rc.1","memofs-v0.1.2","memofs-v0.1.1","v0.6.0-alpha.3","memofs-v0.1.0","v0.6.0-alpha.2","v0.6.0-alpha.1","v0.5.0","v0.5.0-alpha.13","v0.5.0-alpha.12","v0.5.0-alpha.11","v0.5.0-alpha.9","v0.5.0-alpha.8","v0.5.0-alpha.6","v0.5.0-alpha.5","v0.5.0-alpha.4","v0.5.0-alpha.3","v0.5.0-alpha.2","v0.5.0-alpha.1","v0.5.0-alpha.0","v0.4.11","v0.4.10","v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.4.0-pre3","v0.4.0-pre2","v0.4.0-pre1","v0.3.2","v0.3.1","v0.3.0","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97875.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}