Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22028

21
FAUCET Score

CVE-2026-22028 is a medium-severity HTML injection vulnerability affecting Preact versions 10.26.5 through 10.26.9, 10.27.0 through 10.27.2, and 10.28.0 through 10.28.1. It arises from a regression that softens JSON serialization protection, allowing specially crafted JSON payloads to be misinterpreted as valid Virtual DOM nodes under specific conditions. This can lead to arbitrary script execution if not mitigated by a Content Security Policy. The CVSS score is 6.1 (MEDIUM), indicating a network-based attack requiring user interaction with low impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.26.5, < 10.26.10CPE matchmatch criteria
cpe:2.3:a:preactjs:preact:*:*:*:*:*:node.js:*:*
>= 10.27.0, < 10.27.3CPE matchmatch criteria
cpe:2.3:a:preactjs:preact:*:*:*:*:*:node.js:*:*
>= 10.28.0, < 10.28.2CPE matchmatch criteria
cpe:2.3:a:preactjs:preact:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

7.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 14th percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

npmpatch availablevia ghsa
Product: preactFixed in: 10.26.10
npmpatch availablevia ghsa
Product: preactFixed in: 10.27.3
npmpatch availablevia ghsa
Product: preactFixed in: 10.28.2
github_advisoryworkaround availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: streams for Apache Kafka 3Fixed in: com.github.streamshub-console
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-agent-installer-ui-rhel9
redhatno patchvia redhat_api
Product: streams for Apache Kafka 2Fixed in: com.github.streamshub-console
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: automation-platform-ui
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-dashboard-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-mod-arch-gen-ai-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-mod-arch-model-registry-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/logging-view-plugin-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/fluentd-rhel9

Vendor Advisories (2)

redhatCVE-2026-22028Moderate

preact: Preact: Arbitrary script execution via JSON serialization protection bypass

Jan 8, 2026
npmGHSA-36hm-qxxp-pg3mhigh

Preact has JSON VNode Injection issue

Jan 7, 2026

References

github.com / preactjs/preact/security/advisories/GHSA-36hm-qxxp-pg3m
ExploitMitigationVendor Advisory