CVE-2026-23848 | franklioxygen MyTube up to 1.7.70 API Endpoint X-Forwarded-For reliance on untrusted inputs in a security decision (GHSA-59gr-529g-x45h / EUVD-2026-3288)
A vulnerability classified as critical has been found in franklioxygen MyTube up to 1.7.70. The impacted element is an unknown function of the component API Endpoint. Performing a manipulation of the argument X-Forwarded-For results in reliance on untrusted inputs in a security decision.
This vulnerability is known as CVE-2026-23848. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.