VulnSea

CWE-526

CVEs classified under CWE-526, newest first.

5 CVEsRSS

CVE-2026-76227Medium· 5.5
1mo ago

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (renovate/renovate, mend/renovate-ce, renovate-ee-server, renovate-ee-worker >=13.3.0 <13.6.0), fail to restrict enviro…

SunlitEPSS 0.12%via NVD
CVE-2026-75915High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript c…

Twilightdeepseek-tui · deepseek-tuiEPSS 0.62%via NVD
CVE-2026-72648Medium· 6.5
1mo ago

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37)

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive Data (CAPEC-37). When ECK reconciles a Fleet Server r…

Sunlitelastic · elastic_cloud_on_kubernetesEPSS 0.31%via NVD
CVE-2024-11736Medium· 4.9
1y ago

A vulnerability was found in Keycloak

A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can in…

SunlitEPSS 0.77%via NVD
CVE-2024-2700High· 7.0
2y ago

A vulnerability was found in the quarkus-core component

A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus namespace during the application's build, therefore, running the resulting application inherits the values captured at…

TwilightEPSS 0.29%via NVD
CWE-526 vulnerabilities (CVEs) · VulnSea