CVE-2026-34226
EUVD-2026-1689327.03.2026, 22:16
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9 may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(..., { credentials: "include" })` is used. This can leak cookies from origin A to destination B. Version 20.8.9 fixes the issue.EnginsightAffected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| capricorn86 | happy_dom | 𝑥 < 20.8.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References