All 3 CVE vulnerabilities found in secure_headers, with AI-generated Chinese analysis, references, and POCs.
Vendor: Twitter
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-54163 | secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input CWE-79 | 4.7 | Medium | 2026-07-17 |
| CVE-2020-5216 | Limited header injection when using dynamic overrides with user input in RubyGems secure_headers CWE-113 | 4.4 | Medium | 2020-01-23 |
| CVE-2020-5217 | Directive injection when using dynamic overrides with user input in RubyGems secure_headers CWE-95 | 4.4 | Medium | 2020-01-23 |
All 3 known CVE vulnerabilities affecting secure_headers with full Chinese analysis, references, and POCs where available.