Home

Description

Improper input validation in the error message page in Devolutions Server 2025.3.15 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

PUBLISHED Reserved 2026-02-25 | Published 2026-03-03 | Updated 2026-03-03 | Assigner DEVOLUTIONS

Problem types

CWE-20 Improper Input Validation

Product status

Default status
unaffected

Any version before 2025.3.16
affected

References

devolutions.net/security/advisories/DEVO-2026-0005

cve.org (CVE-2026-3204)

nvd.nist.gov (CVE-2026-3204)

Download JSON