Improper Neutralization of Special Elements in Output Used by a Downstream Component in GoAnywhere MFT - CVE-2026-1089
Published: June 19, 2026
GoAnywhere MFT
Detailed vulnerability description
The vulnerability allows a remote attacker to trigger arbitrary DNS lookups and disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in user-controlled HTTP header processing when handling requests. A remote attacker can send a specially crafted request to trigger arbitrary DNS lookups and disclose sensitive information.
The issue may also enable DNS rebinding.