CVE-2026-32993
HIGH
NVD
CVSS Score
8.3
Severity
HIGH
Published
May 13, 2026
Vendor
unknown
Description
Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated attacker to inject arbitrary HTTP header to the response.