
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1089 is a User-Controlled HTTP Header vulnerability in Fortra's GoAnywhere Managed File Transfer (MFT) that allows unauthenticated attackers to trigger arbitrary DNS lookups, conduct DNS rebinding attacks, and cause information disclosure. It affects all versions of GoAnywhere MFT prior to 7.10.0. The CVE was received from Fortra on April 21, 2026, with initial NVD analysis completed on April 23, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Fortra (GitHub Advisory, Fortra Advisory).
The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — 'Injection'). The vulnerability arises because GoAnywhere MFT fails to properly validate or sanitize user-supplied HTTP header values before using them in downstream operations, allowing an attacker to inject values that cause the server to perform DNS lookups to attacker-controlled domains. This network-accessible flaw requires no authentication, no user interaction, and has low attack complexity, making it straightforward to trigger remotely. The primary attack techniques enabled are DNS rebinding — which can be used to bypass same-origin policy protections and pivot to internal network resources — and information disclosure via DNS side-channels (Fortra Advisory, GitHub Advisory).
Successful exploitation results in low confidentiality impact (partial information disclosure) and low availability impact, with no integrity impact. An unauthenticated remote attacker can force the GoAnywhere MFT server to issue DNS queries to attacker-controlled infrastructure, potentially revealing internal network topology, server IP addresses, or other sensitive metadata via DNS side-channels. DNS rebinding attacks could further allow an attacker to bypass browser same-origin restrictions and interact with internal services accessible to the GoAnywhere MFT host, increasing the risk of lateral movement within the network (Fortra Advisory, GitHub Advisory).
Host, X-Forwarded-For, Referer, or a similar header) set to a value pointing to the attacker's domain (e.g., attacker.example.com).Host, X-Forwarded-For, Referer, or custom headers; repeated requests from the same source IP with varying header values targeting DNS-resolvable hostnames.Fortra has released GoAnywhere MFT version 7.10.0 to address this vulnerability; all users should upgrade immediately (Fortra Advisory). For systems that cannot be patched immediately, implement network-level egress filtering to restrict outbound DNS queries from the GoAnywhere MFT server to only trusted, necessary resolvers. Additionally, restrict network access to the GoAnywhere MFT application from untrusted or external sources using firewall rules or network segmentation to reduce the attack surface.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."