CVE-2026-82838 PUBLISHED

Default webserver configuration with incorrect CSP

Assigner: rami.io
Reserved: 31.08.2026 Published: 31.08.2026 Updated: 31.08.2026

The default docker image shipped for Venueless did not properly ensure that uploaded SVG files could not be delivered with executable JavaScript content. A valid Content Security Policy is now set.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
CVSS Score: 6.4

Product Status

Vendor pretix
Product venueless
Versions Default: unaffected
  • affected from 0 to 7dff888 (excl.)

Credits

  • Vignesh M finder

References

Problem Types

  • CWE-80 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) CWE

Impacts

  • CAPEC-63 Cross-Site Scripting (XSS)