CVE-2026-1089

User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and Information Disclosure.

medium 6.5 CVSS 3.1
Published: Apr 21, 2026
Modified: Apr 23, 2026