CVE-2026-39364 | vitejs vite up to 7.3.1/8.0.4 Query Parameter incorrect behavior order: validate before canonicalize (GHSA-v2wj-q39q-566r)
A vulnerability was found in vitejs vite up to 7.3.1/8.0.4. It has been classified as problematic. This vulnerability affects unknown code of the component Query Parameter Handler. Performing a manipulation results in incorrect behavior order: validate before canonicalize.
This vulnerability is identified as CVE-2026-39364. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.