CVE-2026-35253

Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Macaron Tool. Successful attacks of this vulnerability can result in Oracle Macaron Tool failing host address validation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:macaron:0.22.0:*:*:*:*:*:*:*

History

12 May 2026, 19:10

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:macoron:0.22.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:macaron:0.22.0:*:*:*:*:*:*:*
First Time Oracle macaron

10 May 2026, 20:16

Type Values Removed Values Added
CWE CWE-346

06 May 2026, 20:30

Type Values Removed Values Added
CWE CWE-601
CPE cpe:2.3:a:oracle:macoron:0.22.0:*:*:*:*:*:*:*
References () https://www.oracle.com/security-alerts/all-oracle-cves-outside-other-oracle-public-documents.html - () https://www.oracle.com/security-alerts/all-oracle-cves-outside-other-oracle-public-documents.html - Not Applicable
First Time Oracle macoron
Oracle

06 May 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 08:16

Updated : 2026-05-12 19:10


NVD link : CVE-2026-35253

Mitre link : CVE-2026-35253

CVE.ORG link : CVE-2026-35253


JSON object : View

Products Affected

oracle

  • macaron
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-346

Origin Validation Error