CVE-2026-34226

Source
https://cve.org/CVERecord?id=CVE-2026-34226
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34226.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34226
Aliases
Published
2026-03-27T21:17:24.777Z
Modified
2026-04-10T05:43:01.477353Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
Details

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (window.location) instead of the request target URL when fetch(..., { credentials: "include" }) is used. This can leak cookies from origin A to destination B. Version 20.8.9 fixes the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-201",
        "CWE-359"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34226.json"
}
References

Affected packages

Git / github.com/capricorn86/happy-dom

Affected ranges

Type
GIT
Repo
https://github.com/capricorn86/happy-dom
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "20.8.9"
        }
    ]
}

Affected versions

v0.*
v0.0.1
v0.1.0
v0.10.0
v0.10.1
v0.10.6
v0.10.7
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.14.0
v0.2.0
v0.2.16
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.8.3
v0.8.4
v0.8.5
v0.9.0
v10.*
v10.0.0
v10.0.1
v10.0.2
v10.0.3
v10.0.4
v10.0.5
v10.0.6
v10.0.7
v10.1.0
v10.1.1
v10.10.0
v10.10.1
v10.10.2
v10.10.3
v10.10.4
v10.11.0
v10.11.1
v10.11.2
v10.2.0
v10.3.0
v10.3.1
v10.3.2
v10.4.0
v10.5.0
v10.5.1
v10.5.2
v10.5.3
v10.6.0
v10.6.1
v10.6.2
v10.6.3
v10.7.0
v10.8.0
v10.8.1
v10.9.0
v11.*
v11.0.0
v11.0.1
v11.0.2
v11.0.3
v11.0.4
v11.0.5
v11.0.6
v11.1.0
v11.1.1
v11.1.2
v11.2.0
v12.*
v12.0.0
v12.0.1
v12.1.0
v12.1.1
v12.1.2
v12.1.3
v12.1.4
v12.1.5
v12.1.6
v12.1.7
v12.10.0
v12.10.1
v12.10.2
v12.10.3
v12.2.0
v12.2.1
v12.2.2
v12.3.0
v12.4.0
v12.5.0
v12.5.1
v12.6.0
v12.7.0
v12.8.0
v12.8.1
v12.9.0
v12.9.1
v12.9.2
v13.*
v13.0.0
v13.0.1
v13.0.2
v13.0.3
v13.0.4
v13.0.5
v13.0.6
v13.0.7
v13.1.0
v13.1.1
v13.1.2
v13.1.3
v13.1.4
v13.10.0
v13.10.1
v13.2.0
v13.2.1
v13.2.2
v13.3.0
v13.3.1
v13.3.2
v13.3.3
v13.3.4
v13.3.5
v13.3.6
v13.3.7
v13.3.8
v13.4.0
v13.4.1
v13.5.0
v13.5.1
v13.5.2
v13.5.3
v13.6.0
v13.6.1
v13.6.2
v13.7.0
v13.7.1
v13.7.2
v13.7.3
v13.7.4
v13.7.5
v13.7.6
v13.7.7
v13.7.8
v13.8.0
v13.8.1
v13.8.2
v13.8.3
v13.8.4
v13.8.5
v13.8.6
v13.9.0
v14.*
v14.0.0
v14.1.0
v14.1.1
v14.1.2
v14.10.0
v14.10.1
v14.10.2
v14.10.3
v14.11.0
v14.11.1
v14.11.2
v14.11.3
v14.11.4
v14.12.0
v14.12.1
v14.12.2
v14.12.3
v14.2.0
v14.2.1
v14.3.0
v14.3.1
v14.3.10
v14.3.2
v14.3.3
v14.3.4
v14.3.5
v14.3.6
v14.3.7
v14.3.8
v14.3.9
v14.4.0
v14.5.0
v14.5.1
v14.5.2
v14.6.0
v14.6.1
v14.6.2
v14.7.0
v14.7.1
v14.8.0
v14.8.1
v14.8.2
v14.8.3
v14.9.0
v15.*
v15.0.0
v15.1.0
v15.10.0
v15.10.1
v15.10.2
v15.10.3
v15.10.4
v15.10.5
v15.10.6
v15.10.7
v15.10.8
v15.11.0
v15.11.1
v15.11.2
v15.11.3
v15.11.4
v15.11.5
v15.11.6
v15.11.7
v15.2.0
v15.3.0
v15.3.1
v15.3.2
v15.4.0
v15.4.1
v15.4.2
v15.4.3
v15.5.0
v15.6.0
v15.6.1
v15.7.0
v15.7.1
v15.7.2
v15.7.3
v15.7.4
v15.8.0
v15.8.1
v15.8.2
v15.8.3
v15.8.4
v15.8.5
v15.9.0
v16.*
v16.0.0
v16.0.1
v16.1.0
v16.2.0
v16.2.1
v16.2.2
v16.2.3
v16.2.4
v16.2.5
v16.2.6
v16.2.7
v16.2.8
v16.2.9
v16.3.0
v16.4.0
v16.4.1
v16.4.2
v16.4.3
v16.5.0
v16.5.1
v16.5.2
v16.5.3
v16.6.0
v16.7.0
v16.7.1
v16.7.2
v16.7.3
v16.8.0
v16.8.1
v17.*
v17.0.0
v17.0.1
v17.0.2
v17.0.3
v17.0.4
v17.1.0
v17.1.1
v17.1.10
v17.1.11
v17.1.12
v17.1.13
v17.1.2
v17.1.3
v17.1.4
v17.1.5
v17.1.6
v17.1.7
v17.1.8
v17.1.9
v17.2.0
v17.2.1
v17.2.2
v17.2.3
v17.2.4
v17.3.0
v17.3.1
v17.3.2
v17.4.0
v17.4.1
v17.4.2
v17.4.3
v17.4.4
v17.4.5
v17.4.6
v17.4.7
v17.4.8
v17.4.9
v17.5.0
v17.5.1
v17.5.2
v17.5.3
v17.5.4
v17.5.5
v17.5.6
v17.5.7
v17.5.8
v17.5.9
v17.6.0
v17.6.1
v17.6.2
v17.6.3
v18.*
v18.0.0
v18.0.1
v19.*
v19.0.0
v19.0.1
v19.0.2
v20.*
v20.0.0
v20.0.1
v20.0.10
v20.0.11
v20.0.2
v20.0.3
v20.0.4
v20.0.5
v20.0.6
v20.0.7
v20.0.8
v20.0.9
v20.1.0
v20.1.1
v20.2.0
v20.3.0
v20.3.1
v20.3.2
v20.3.3
v20.3.4
v20.3.5
v20.3.6
v20.3.7
v20.3.8
v20.3.9
v20.4.0
v20.5.0
v20.5.1
v20.5.2
v20.5.3
v20.5.4
v20.5.5
v20.6.0
v20.6.1
v20.6.2
v20.6.3
v20.6.4
v20.6.5
v20.7.0
v20.7.1
v20.7.2
v20.8.0
v20.8.1
v20.8.2
v20.8.3
v20.8.4
v20.8.5
v20.8.6
v20.8.7
v20.8.8
v8.*
v8.3.0
v8.3.1
v8.3.2
v8.4.0
v8.4.1
v8.4.2
v8.4.3
v8.4.4
v8.5.0
v8.6.0
v8.7.0
v8.7.1
v8.7.2
v8.7.3
v8.7.4
v8.7.5
v8.7.6
v8.8.0
v8.9.0
v9.*
v9.0.0
v9.0.1
v9.1.0
v9.1.1
v9.1.10
v9.1.2
v9.1.3
v9.1.4
v9.1.5
v9.1.6
v9.1.7
v9.1.8
v9.1.9
v9.10.0
v9.10.1
v9.10.2
v9.10.3
v9.10.4
v9.10.5
v9.10.6
v9.10.7
v9.10.8
v9.10.9
v9.11.0
v9.12.0
v9.13.0
v9.13.1
v9.14.0
v9.15.0
v9.16.0
v9.17.0
v9.18.0
v9.18.1
v9.18.2
v9.18.3
v9.19.0
v9.19.1
v9.19.2
v9.2.0
v9.2.1
v9.20.0
v9.20.1
v9.20.2
v9.20.3
v9.3.0
v9.3.1
v9.3.2
v9.4.0
v9.5.0
v9.5.1
v9.6.0
v9.6.1
v9.7.0
v9.7.1
v9.8.0
v9.8.1
v9.8.2
v9.8.3
v9.8.4
v9.9.0
v9.9.1
v9.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34226.json"