Loading HuntDB...

GHSA-x2qc-mfcw-3v2v

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

Related CVEs

Key Information

GHSA ID
GHSA-x2qc-mfcw-3v2v
Published
May 14, 2022 12:53 AM
Last Modified
May 14, 2022 12:53 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.