CVE-2026-43510
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
07/05/2026
Last modified:
07/05/2026
Description
manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assign domain manager privileges for domains not already in another organization. Fixed in 1.176.0 on or around 2026-04-30.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
7.60
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/cisagov/manage.get.gov/issues/4858
- https://github.com/cisagov/manage.get.gov/pull/4900
- https://github.com/cisagov/manage.get.gov/releases/tag/v1.176.0
- https://github.com/cisagov/manage.get.gov/security/advisories/GHSA-6wrg-x3j6-x464
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-121-01.json
- https://www.cve.org/CVERecord?id=CVE-2026-43510



