CWE-200
CVEs classified under CWE-200, newest first.
823 CVEsRSS
CVE-2026-59155NoneNezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full resource objects including plaintext third-party API …
CVE-2026-57219NonePoCRabbitMQ is a messaging and streaming broker
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secre…
CVE-2026-55664Medium· 4.3Grist is spreadsheet software using Python as its formula language
Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was act…
GHSA-g936-7jqj-mwv8Critical· 9.0TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
TSDProxy: Internal proxy auth token forwarded to backend services enables management API escalation
CVE-2026-59216High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the…
CVE-2026-48828Medium· 6.5The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) …
CVE-2026-49487Medium· 6.5In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking
In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator passed a secret (for example a provider API key) into its trigger, a…
CVE-2026-48892Medium· 6.5The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…
The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options wh…
CVE-2026-48891Medium· 4.3A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …
A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of …
GHSA-vjc7-jrh9-9j86Critical· 10.09router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats
CVE-2026-55792MediumCraft CMS: Sensitive File Disclosure / Server-Side File Read
Craft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-55500Critical· 9.99routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover
GHSA-x76w-8c62-48mgMediumCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
CVE-2026-56646Medium· 6.5Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-25038NoneGitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-24451NoneGitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
CVE-2026-14611Medium· 4.3A vulnerability has been found in DeepMyst Mysti up to 0.4.0
A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of the file src/managers/MemoryManager.ts of the component Per-Project Auto-Memory Handler. Such manipulation of the arg…
CVE-2026-10055High· 8.5In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…
CVE-2026-9546High· 7.5PoCA vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal st…
CVE-2026-9545High· 7.5PoCIn this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libc…
GHSA-gj2h-2fpw-fhv9Medium@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
@nuxt/ui: UAuthForm / UForm SSR markup omits `method`, leaking credentials via GET if submitted before hydration
CVE-2026-50200High· 7.5Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords
GHSA-mr9h-45p9-fg8hMedium· 4.3Froxlor: Authenticated customers can read other customers' allowed sender aliases
Froxlor: Authenticated customers can read other customers' allowed sender aliases
CVE-2026-53815High· 6.5OpenClaw: Message read actions could skip channel allowlist checks
OpenClaw: Message read actions could skip channel allowlist checks
CVE-2026-53814High· 8.4OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
GHSA-mhq8-78pj-5j79High· 7.1OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
GHSA-vh4v-2xq2-g5cgMediumORAS Go forwards registry credentials across registry redirects
ORAS Go forwards registry credentials across registry redirects
GHSA-9c3v-684m-579cMedium· 6.5OpenClaw MCP SSE redirects could forward Authorization headers
OpenClaw MCP SSE redirects could forward Authorization headers
GHSA-vjjx-rfw4-rmfcMedium· 6.5SurrealDB: Graph traversal bypasses table SELECT permissions
SurrealDB: Graph traversal bypasses table SELECT permissions
CVE-2026-49988Mediumrepomix: attach_packed_output can bypass file-read secret scanning for supported local files
repomix: attach_packed_output can bypass file-read secret scanning for supported local files