VulnSea

CWE-1327

CVEs classified under CWE-1327, newest first.

9 CVEsRSS

CVE-2026-57123Critical· 9.8
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authenticati…

MidnightMervinPraison · praisonaiagentsEPSS 0.47%via NVD
CVE-2026-75021High· 8.1
2w ago

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector to a broadly reachable address instead of the intended loopback. As a result the debug…

Twilightfastify-cli · fastify-cliEPSS 0.42%via NVD
CVE-2026-82456Critical· 10.0PoC
3w ago

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface…

AbyssalEPSS 1.4%via NVD
CVE-2026-72924None
4w ago

GitHub CLI (gh) is GitHub's official command line tool

GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a servi…

SunlitEPSS 0.18%via NVD
CVE-2026-16503Critical· 9.1
1mo ago

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres"

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, th…

MidnightEPSS 0.32%via NVD
CVE-2026-47873High· 8.0
1mo ago

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for E…

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for E…

TwilightEPSS 0.20%via NVD
CVE-2026-55641High· 8.2
2mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by reading the client-controlled Host header, allowing a remote unauthenticated attacker to send Host: localhost and bypas…

TwilightEPSS 0.32%via NVD
GHSA-x227-pf99-vffgCritical· 9.8
3mo ago

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in

Midnightpraisonaiagents · praisonaiagentsvia GHSA
CVE-2026-42503High· 8.8
4mo ago

gopls by default communicates via pipe

gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen is given a value without an explicit host (e.g. :8080), or -port is used, gopls will listen on 0.0.0.0.  As a result…

Twilightgolang · goplsEPSS 0.21%via NVD
CWE-1327 vulnerabilities (CVEs) · VulnSea