CVE-2026-25155: Qwik

High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.

Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.

Affected products

  • Qwik Qwik: before 1.12.0 (fixed in 1.12.0)

Published 2026-02-03. Last modified 2026-06-17.