CVE-2026-42329

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker can misuse it to redirect the user to a malicious website controlled by an attacker. Version 2.4.28 fixes the issue.
Configurations

No configuration.

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Iris es una plataforma web colaborativa que ayuda a los respondedores de incidentes a compartir detalles técnicos durante las investigaciones. Las versiones anteriores a la 2.4.28 contienen una debilidad donde un atacante puede hacer un uso indebido de ella para redirigir al usuario a un sitio web malicioso controlado por un atacante. La versión 2.4.28 soluciona el problema.

08 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-vjc3-7jwv-j9qf - () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-vjc3-7jwv-j9qf -

04 Jun 2026, 22:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/05/19/7 -

04 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 21:16

Updated : 2026-07-22 20:10


NVD link : CVE-2026-42329

Mitre link : CVE-2026-42329

CVE.ORG link : CVE-2026-42329


JSON object : View

Products Affected

No product.

CWE
CWE-602

Client-Side Enforcement of Server-Side Security