CVE-2026-25155 | [qwik-city] CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.
Conclusion & alert: CVE-2026-25155 is rated Low Risk (23.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.01%).Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2026-25155
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
GHSA-vm6g-8r4h-22x8 · Severity: medium · Ecosystem: npm — Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Affected software / configurations for CVE-2026-25155