CVE-2026-44342
New API is vulnerable to CSRF through user email binding
描述
## Summary The email and WeChat account binding endpoints used GET requests for state-changing account operations. In deployments where session cookies could be sent on cross-site navigations, an attacker could trigger a logged-in user's browser to bind an attacker-controlled email address or OAuth identity. Affected endpoints included: - `GET /api/oauth/email/bind` - `GET /api/oauth/wechat/bind` ## Impact A successful attack could change account binding state. For email binding, the attacker could bind an email address they control and then attempt follow-on account recovery flows. The default session cookie configuration uses `SameSite=Strict`, which mitigates common cross-site navigation attacks in modern browsers, so the issue is rated Medium. ## Affected versions Versions before `v0.12.0-alpha.1` are affected. ## Patches This issue is fixed in `v0.12.0-alpha.1`. The fix changes email and WeChat binding routes from GET to POST and reads parameters from a JSON request body instead of query parameters. The same change set also normalizes password reset responses to avoid disclosing whether an email is registered. ## Workarounds If upgrading immediately is not possible, ensure session cookies are configured with strict SameSite behavior and block GET requests to `/api/oauth/email/bind` and `/api/oauth/wechat/bind` at the reverse proxy. ## Resources - Fixed by commit `e099117c61391abdf888fb75e382a582e550bd0e`. - Relevant code paths: `router/api-router.go` and `controller/user.go`.
如何修補 CVE-2026-44342
要修補 CVE-2026-44342,請將受影響套件升級到下列已修補版本。
- —升級至 0.12.0-alpha.1 或更新版本
CVE-2026-44342 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.12.0-alpha.1