VulnSea

CWE-522

CVEs classified under CWE-522, newest first.

135 CVEsRSS

CVE-2026-54422Medium· 5.5
1mo ago

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

SunlitEPSS 0.12%via NVD
CVE-2026-59891Critical· 9.6PoC
2mo ago

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry

Abyssalsigstore · @sigstore/ociEPSS 0.47%via GHSA
GHSA-94pj-82f3-465wMedium· 5.3
2mo ago

Guzzle: Proxy-Authorization headers can be sent to origin servers

Guzzle: Proxy-Authorization headers can be sent to origin servers

Sunlitguzzlehttp · guzzlehttp/guzzlevia GHSA
CVE-2026-16104Medium· 4.3
2mo ago

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask se…

Sunlitredhat · build_of_keycloakEPSS 0.26%via NVD
CVE-2026-44979None
2mo ago

@hapi/wreck is an HTTP client utility

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, and the standard credential header Proxy-Authorization is fo…

SunlitEPSS 0.42%via NVD
CVE-2026-47282Medium· 6.5
2mo ago

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Sunlitmicrosoft · visual_studio_codeEPSS 0.87%via NVD
CVE-2026-55431High· 7.7
2mo ago

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Twilightcoder · github.com/coder/coder/v2EPSS 0.34%via GHSA
CVE-2026-9079Critical· 9.8PoC⚖ disputed
2mo ago

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.

Abyssalhaxx · curlEPSS 0.58%via NVD
CVE-2026-8926Critical· 9.1PoC
2mo ago

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set …

Abyssalhaxx · curlEPSS 0.44%via NVD
GHSA-grc3-2j34-p6gmMedium
2mo ago

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

OpenClaw: message.action forwarding could send Gateway credentials to model-supplied loopback URLs

Sunlitopenclaw · openclawvia GHSA
CVE-2026-50151Medium· 5.9
2mo ago

oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)

A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.38%via CSAF
GHSA-vh4v-2xq2-g5cgMedium
2mo ago

ORAS Go forwards registry credentials across registry redirects

ORAS Go forwards registry credentials across registry redirects

Sunlitoras-go · oras.land/oras-go/v2via GHSA
GHSA-9c3v-684m-579cMedium· 6.5
2mo ago

OpenClaw MCP SSE redirects could forward Authorization headers

OpenClaw MCP SSE redirects could forward Authorization headers

Sunlitopenclaw · openclawvia GHSA
CVE-2026-44938High· 8.8
2mo ago

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent

Twilightrancher · github.com/rancher/fleetEPSS 0.44%via GHSA
CVE-2025-7386Medium· 6.8
2mo ago

Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver

Information exposure vulnerability in Hitachi Storage Navigator. This issue affects Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8: before DKCMAIN Ver. 90-09-24-00/00, SVP Ver. 90-09-24/00, befo…

SunlitEPSS 0.38%via NVD
CVE-2026-50017Medium
2mo ago

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

Sunlitpnpm · pnpmEPSS 0.44%via GHSA
CVE-2026-55180Medium· 6.5
2mo ago

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

Sunlitpnpm · pnpmEPSS 0.37%via GHSA
CVE-2026-54276Medium· 6.1
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…

Sunlitaiohttp · aiohttpEPSS 0.31%via NVD
CVE-2026-55885Medium· 6.8
3mo ago

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Sunlitgetgrav · getgrav/gravEPSS 0.27%via GHSA
GHSA-f989-c77f-r2cqHigh· 8.2
3mo ago

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

Twilightcrawl4ai · crawl4aivia GHSA
GHSA-x7cf-6gp3-q5f8Medium· 7.1
3mo ago

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

Duplicate Advisory: MCP Streamable HTTP redirects could forward configured custom headers to another origin

Sunlitopenclaw · openclawvia GHSA
CVE-2026-53632Medium
3mo ago

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows

Sunlitlaunch-editor · launch-editorEPSS 0.43%via GHSA
CVE-2026-48022Medium· 6.5
3mo ago

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects

Sunlithapi · @hapi/wreckEPSS 0.18%via GHSA
CVE-2026-6253Medium· 5.9PoC
4mo ago

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy nee…

Twilighthaxx · curlEPSS 0.72%via NVD
CVE-2026-28961Medium· 4.6
4mo ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical access to a locked device may be able to view sensitive user information.

Sunlitapple · macosEPSS 0.24%via NVD
CVE-2026-23927Medium· 6.5
4mo ago

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter

A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a…

Sunlitzabbix · zabbixEPSS 0.22%via NVD
CVE-2025-31976Medium· 4.8
4mo ago

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to potentially misuse them, if exfiltrat…

Sunlithcltech · bigfix_service_managementEPSS 0.16%via NVD
CVE-2025-15621Medium· 6.0
5mo ago

Insufficiently Protected Credentials in Sparx Systems Pty Ltd

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

Sunlitsparxsystems · enterprise_architectEPSS 0.11%via NVD
CVE-2026-4819Medium· 4.9
5mo ago

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Sunlitsearch-guard · flxEPSS 0.21%via NVD
CVE-2026-3783Medium· 5.3PoC
6mo ago

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is re…

Twilighthaxx · curlEPSS 0.45%via NVD
CWE-522 vulnerabilities (CVEs) — page 4 · VulnSea