CVE-2023-29476
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+.
Published 2024-12-14. Last modified 2026-06-17.