CVE-2026-25151

Qwik City has a CSRF Protection Bypass via Content-Type Header Validation

Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted or multi-valued Content-Type headers. This issue has been patched in version 1.19.0.


We have discovered 12,936 live websites that are affected by CVE-2026-25151.

Run a Free Instant Scan




Affected Software

Product  Qwik
Category Web Application Frameworks
Vulnerable Domains12,936 live websites (100% of Qwik install base)
Vulnerable Versions
  • from 0 through 1.19
Vulnerable Versions Count40 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Feb 3, 2026
  • Updated - Feb 4, 2026

Website Distribution by Country

Number of websites using CVE-2026-25151
United States9,502 websites
GB311 websites
Germany55 websites
Canada32 websites
Iran12 websites
France10 websites
Poland9 websites
Czech Republic8 websites
Portugal8 websites

Website Distribution by TLD

Number of websites using CVE-2026-25151
.com8,043 websites
.de675 websites
.net450 websites
.info427 websites
.co.uk308 websites
.org144 websites
.co21 websites
.at8 websites
.fr8 websites
.io8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-25151

Top websites that are affected by CVE-2026-25151. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.jobs United States*,***
***********.com United States*,***
**.com United States*,***
******.at Austria*,***
***********.com United States**,***
*******.online United States**,***
*******.com United States**,***
********.com United States**,***
***.ch United States**,***
*****.com United States**,***
See full domain list

FAQ

CVE-2026-25151 is Cross-Site Request Forgery (CSRF) in Qwik
A total of 12,936 websites have been identified as vulnerable to CVE-2026-25151, based on global website indexing conducted by WebTechSurvey.
The Qwik is affected by the CVE-2026-25151 vulnerability.
Qwik versions up to 1.19 are vulnerable to CVE-2026-25151.
CVE-2026-25151 is resolved in version 1.19 of Qwik.