CVE-2026-31382
MEDIUM
NVD
CVSS Score
6.1
Severity
MEDIUM
Published
Mar 20, 2026
Vendor
unknown
Description
The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.