CWE-201
CVEs classified under CWE-201, newest first.
82 CVEsRSS
CVE-2026-59809Medium· 4.9SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets
SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL con…
CVE-2026-63481MediumHurl is a command line tool that runs and tests HTTP requests defined in plain text files
Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth cre…
CVE-2026-74945Medium· 6.5PoCInformation disclosure in the Graphics: Text component
Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
CVE-2026-47717High· 7.5PoCFUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabl…
CVE-2026-16637Medium· 6.5OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
CVE-2026-64652Low· 3.3GitHub CLI (gh) is GitHub's official command line tool
GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part …
CVE-2026-66684Medium· 5.3Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-20484NoneIn TFA, there is a possible information disclosure due to a missing permission check
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for expl…
GHSA-mqq9-gxg5-m58gHigh· 5.9Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-mjrx-74jh-7xgwHigh· 5.9Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
CVE-2026-67355Medium· 5.9guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies inten…
CVE-2026-67354Medium· 5.9guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') …
CVE-2026-67322High· 7.5GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from()
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL befor…
CVE-2026-67425High· 8.6Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-64643MediumNext.js: Unauthenticated disclosure of internal Server Function endpoints
Next.js: Unauthenticated disclosure of internal Server Function endpoints
GHSA-rwj8-pgh3-r573High· 7.5GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
CVE-2026-13380High· 7.5VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured with…
GHSA-wm3w-8rrp-j577Medium· 5.9Guzzle: Host-only cookie scope is not preserved
Guzzle: Host-only cookie scope is not preserved
GHSA-h95v-h523-3mw8Medium· 5.9Guzzle: URI fragments disclosed in redirect Referer headers
Guzzle: URI fragments disclosed in redirect Referer headers
GHSA-94pj-82f3-465wMedium· 5.3Guzzle: Proxy-Authorization headers can be sent to origin servers
Guzzle: Proxy-Authorization headers can be sent to origin servers
CVE-2026-10051Medium· 5.3jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)
A flaw was found in Eclipse Jetty. This vulnerability allows a remote attacker to cause the server to retain HTTP/1.1 request trailers from a prior connection. Consequently, subsequent requests made over the same connection may unintention…
CVE-2026-49853High· 7.7tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…
CVE-2026-56460Medium· 6.5HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks against the system.
CVE-2026-42505Medium· 5.3Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.
CVE-2026-8927Critical· 9.1PoCWhen reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates agains…
CVE-2026-8924Critical· 9.1PoC⚖ disputedA flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmit…
CVE-2026-11856Critical· 9.8PoC⚖ disputedSuccessfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…
CVE-2026-13437Medium· 6.5Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authenticatio…
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authenticatio…
CVE-2026-55180Medium· 6.5pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run