LiveActive security incident?Get immediate response
CVE archive

April 2025

Browse CVE records published in April 2025, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 3966 matching CVEs · Page 14 of 80.

Medium · CVSS 4.7

CVE-2025-66286: Webkitgtk: authorization bypass through webpage::send-request signal handler

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.

Published Apr 23, 2026 · Updated Apr 28, 2026