CVE-2026-25155: Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
A typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-25155 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →