CVE-2025-66286

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026

Description

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the<br /> WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.