{"api_version":"1","generated_at":"2026-08-08T04:36:50+00:00","cve":"CVE-2026-18487","urls":{"html":"https://cve.report/CVE-2026-18487","api":"https://cve.report/api/cve/CVE-2026-18487.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18487","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18487"},"summary":{"title":"Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()","description":"A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.","state":"PUBLISHED","assigner":"fedora","published_at":"2026-08-06 22:16:50","updated_at":"2026-08-07 16:17:22"},"problem_types":["CWE-451","CWE-451 User Interface (UI) Misrepresentation of Critical Information"],"metrics":[{"version":"3.1","source":"patrick@puiterwijk.org","type":"Secondary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://gitlab.gnome.org/GNOME/epiphany/-/commit/0dde1d369458ac5c44b74b5ad3c433f825f6f8af","name":"https://gitlab.gnome.org/GNOME/epiphany/-/commit/0dde1d369458ac5c44b74b5ad3c433f825f6f8af","refsource":"patrick@puiterwijk.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-18487","name":"https://access.redhat.com/security/cve/CVE-2026-18487","refsource":"patrick@puiterwijk.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897","name":"https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897","refsource":"patrick@puiterwijk.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509570","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2509570","refsource":"patrick@puiterwijk.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18487","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18487","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"GNOME","product":"Epiphany","version":"affected 49.2 * semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-07-10T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-07-07T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Red Hat would like to thank Fernando Munoz for reporting this issue.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"18487","cve":"CVE-2026-18487","epss":"0.003180000","percentile":"0.242210000","score_date":"2026-08-07","updated_at":"2026-08-08 00:14:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-18487","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-07T15:37:47.946112Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-07T15:39:27.740Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://gitlab.gnome.org/GNOME/epiphany","defaultStatus":"unaffected","packageName":"epiphany","product":"Epiphany","vendor":"GNOME","versions":[{"lessThan":"*","status":"affected","version":"49.2","versionType":"semver"}]}],"credits":[{"lang":"en","value":"Red Hat would like to thank Fernando Munoz for reporting this issue."}],"datePublic":"2026-07-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-451","description":"User Interface (UI) Misrepresentation of Critical Information","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-06T16:32:39.361Z","orgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","shortName":"fedora"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-18487"},{"name":"RHBZ#2509570","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2509570"},{"url":"https://gitlab.gnome.org/GNOME/epiphany/-/commit/0dde1d369458ac5c44b74b5ad3c433f825f6f8af"},{"url":"https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897"}],"timeline":[{"lang":"en","time":"2026-07-10T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-07-07T00:00:00.000Z","value":"Made public."}],"title":"Epiphany: address bar / host spoofing via userinfo in ephy_uri_get_decoded_host()","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-451: User Interface (UI) Misrepresentation of Critical Information"}},"cveMetadata":{"assignerOrgId":"92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5","assignerShortName":"fedora","cveId":"CVE-2026-18487","datePublished":"2026-08-06T16:32:39.361Z","dateReserved":"2026-07-31T13:30:18.349Z","dateUpdated":"2026-08-07T15:39:27.740Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-06 22:16:50","lastModifiedDate":"2026-08-07 16:17:22","problem_types":["CWE-451","CWE-451 User Interface (UI) Misrepresentation of Critical Information"],"metrics":{"cvssMetricV31":[{"source":"patrick@puiterwijk.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-07T15:37:47.946112Z","id":"CVE-2026-18487","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18487","Ordinal":"1","Title":"Epiphany: address bar / host spoofing via userinfo in ephy_uri_g","CVE":"CVE-2026-18487","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18487","Ordinal":"1","NoteData":"A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and security menus will display the safe website (trusted.com) but it will actually load the attacker website (attacker.com) on the screen. This allows attackers to create convincing phishing pages to trick users into trusting a malicious site.","Type":"Description","Title":"Epiphany: address bar / host spoofing via userinfo in ephy_uri_g"}]}}}