Cyber Resilience

CWE · MITRE source

CWE-942Permissive Cross-domain Security Policy with Untrusted Domains

Abstraction: Variant · CVEs in our corpus: 122

The product uses a web-client protection mechanism such as a Content Security Policy (CSP) or cross-domain policy file, but the policy includes untrusted domains with which the web client is allowed to communicate.

If a cross-domain policy file includes domains that should not be trusted, such as when using wildcards under a high-level domain, then the application could be attacked by these untrusted domains. In many cases, the attack can be launched without the victim even being aware of it.

Last updated: 22 August 2026 00:25 UTC

OWASP Top 10 for Web (2025)

This weakness contributes to A02:2025 Security Misconfiguration.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-01
  • PR.PS-06
  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.4.3
  • V3.4.6
  • V3.5.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-22812 7.78.80.16972026-01-12
CVE-2022-31736 7.59.80.01062022-12-22
CVE-2022-26969 7.59.80.00932022-12-26
CVE-2026-597267.410.00.00482026-07-09
CVE-2024-25124 7.19.40.00662024-02-21
CVE-2023-38125 6.88.80.01342024-05-03
CVE-2026-287926.89.60.00532026-03-12
CVE-2026-34449 6.89.60.00502026-03-31
CVE-2026-8948 6.89.10.00422026-05-19
CVE-2026-464096.79.60.00362026-08-07
CVE-2021-34435 6.68.80.00602021-09-01
CVE-2026-30924 6.69.60.00262026-03-19
CVE-2026-34227 6.58.80.00402026-03-31
CVE-2026-617366.59.30.00312026-07-15
CVE-2024-11071 6.38.80.00192025-04-07
CVE-2026-1181 6.39.00.00322026-01-19
CVE-2026-591486.38.80.00172026-07-09
CVE-2024-41659 6.28.10.00642024-08-20
CVE-2024-41657 6.28.10.00792024-08-20
CVE-2026-560766.28.10.00742026-06-18
CVE-2023-23464 6.18.10.00482023-02-15
CVE-2023-46098 6.18.00.00622023-11-14
CVE-2025-43480 6.18.10.00462025-11-04
CVE-2026-33010 6.18.10.00392026-03-20
CVE-2022-47717 6.07.50.00732023-02-01