CVE-2019-18949: Snowhaze

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration.

Affected products

  • Snowhaze Snowhaze: before 2.6.6 (fixed in 2.6.6)

Published 2019-11-14. Last modified 2026-06-17.