{"api_version":"v1","generated_at":"2026-10-07T01:05:00+00:00","product":{"cve_count":1,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-tauri-tauri-plugin-http-c882eb71a092","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"tauri-plugin-http","next_cursor":null,"observations":[{"affected":"tauri-plugin-http: 2.0.0 \u2264 2.6.1, 2.7.0 \u2264 *","affected_versions_present":true,"cve_id":"CVE-2026-95623","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-95623","fixed":"Upgrade to tauri-plugin-http 2.7.0 or later and turn on the new scopeRedirects option. Both steps are needed. The fix is opt-in, so 2.7.0 on its own still follows a redirect out of scope; the option is what makes the plugin check every hop. Tauri made it opt-in because a redirect that leaves the scope now fails, which changes behaviour for apps that were relying on it.; {\"plugins\": {\"http\": {\"scopeRedirects\": true}}}; Nothing in the 2.0.0 to 2.6.1 range has a fix available.","last_modified":"2026-09-22T17:17:16.133Z","patch_url":"https://github.com/tauri-apps/plugins-workspace/security/advisories/GHSA-2rxp-f4w5-6hjr","primary_source":"","published":"2026-09-22T10:52:20.006Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Tauri"}}
