CVE-2025-66286
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026
Description
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the<br />
WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.
Impact
Base Score 3.x
4.70
Severity 3.x
MEDIUM



