CVE-2025-50579
MEDIUMDescription
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote attacker-controlled server, potentially leading to unauthorized actions within the application.
Is your site exposed to CVE-2025-50579?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| jc21 | nginx_proxy_manager |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-50579? +
How severe is CVE-2025-50579? +
What products are affected by CVE-2025-50579? +
How do I check if I'm vulnerable to CVE-2025-50579? +
Related Vulnerabilities
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) …
Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative …
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a …
In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application …
An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may …