Under certain external upload configurations, Payload could send authentication data to a destination that was not verified as trusted. If the affected request contained a valid session, this could expose that session to an unintended recipient.
You are affected if:
Payload now validates the destination before forwarding authentication data and reapplies that validation when a request changes destination.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
It is recommended to update all Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
If you cannot, a valid workaround exists:
{
"cwe_ids": [
"CWE-200",
"CWE-346"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T20:29:41Z",
"nvd_published_at": "2026-10-06T17:17:22Z",
"severity": "HIGH"
}