CVE-2026-0301
published 2026-08-13CVE-2026-0301: An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access…
PriorityP417low1.7CVSS 4.0
AVNACLATPPRNUINVCLVINVANSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUNRUVDREMUAmber
EPSS
0.31%
24.2th percentile
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| palo_alto_networks | cloud_ngfw | — | — |
| palo_alto_networks | pan-os | >= 10.2.0 < 10.2.8 | 10.2.8 |
| palo_alto_networks | pan-os | >= 11.1.0 < 11.1.16-h1 | 11.1.16-h1 |
| palo_alto_networks | prisma_access | >= 10.2.0 < 10.2.10 | 10.2.10 |
| paloalto | cloud_ngfw | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| vapor | leaf-kit | >= 0 < 1.4.1 | 1.4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-OS: Information Disclosure Vulnerability in URL Filtering
vendor_paloalto·CVSS 6.3
CVE-2026-0301 CWE-908 PAN-OS: Information Disclosure Vulnerability in URL Filtering
PAN-OS: Information Disclosure Vulnerability in URL Filtering
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
Affected products: Cloud NGFW, PAN-OS, Prisma Access
Solution: VERSION MINOR VERSION SUGGESTED SOLUTION
Cloud NGFW* Customers who prefer to upgrade can work with Palo Alto
Networks support to schedule an on-demand software upgrade.
PAN-OS 12.1 12.1.2 through 12.1.6-h* No action needed.
PAN-OS 11.2 11.2.0 through 11.2.12 No action needed.
PAN-OS 11.1 11.1.0 through 11.1.16-h* Upgrade to 11.1.16-h1 or 11.1.17 or later.
PAN-OS 10.2 10.2.0 through 10.2.* Upgrade to 10.2.8 or 11.1.17 or later
GHSA
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
ghsa_unreviewed·2026-08-13
CVE-2026-0301 [LOW] CWE-908 An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
GHSA
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
ghsa·2026-02-19
CVE-2026-27120 [MEDIUM] CWE-75 Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
### Summary
`htmlEscaped` in leaf-kit will only escape html special characters if the extended grapheme clusters match, which allows bypassing escaping by using an extended grapheme cluster containing both the special html character and some additional characters. In the case of html attributes, this can lead to XSS if there is a leaf variable in the attribute that is user controlled.
### Details
Relevant code:
https://github.com/vapor/leaf-kit/blob/main/Sources/LeafKit/String%2BHTMLEscape.swift#L14
Strings in Swift are based on extended grapheme clusters. HTML on the other hand is based on unicode characters.
For example if you have the sequence "́ (U+0022 Quotation mark followed by U+0301
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-13
Published