What is CVE-2026-70605?
CVE-2026-70605 is a vulnerability in the Electron framework where net.fetch() and net.request() did not restrict redirect schemes when following HTTP redirects. A remote server could potentially redirect to dangerous schemes. Users should update to versions 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 or later.
Azərbaycanca: Electron framework-də aşkarlanan CVE-2026-70605 zəifliyi net.fetch() və net.request() funksiyalarının HTTP yönləndirmələrini emal edərkən yönləndirmə sxemlərini məhdudlaşdırmaması ilə bağlıdır. Bu, uzaq serverə potensial olaraq təhlükəli sxemlərə yönləndirmə etməyə imkan verə bilər. Təsirə məruz qalan versiyaları 39.8.8, 40.9.0, 41.2.1 və 42.0.0-beta.3 və daha yeni versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which Electron functions are affected by CVE-2026-70605?
The vulnerability is related to the net.fetch() and net.request() functions not restricting redirect schemes when following HTTP redirects.
Which versions are recommended to update to for fixing CVE-2026-70605?
It is recommended to update to versions 39.8.8, 40.9.0, 41.2.1, 42.0.0-beta.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.