VulnSea

warp-tech has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 5.7 (medium), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.7
Publish → KEV
Last 90 days
7 prev 0

Products

  • warpgate 7
7
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

warp-tech vulnerabilities

CVEs affecting warp-tech, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-91167Medium· 6.0
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not …

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-91166Medium· 5.7
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead pas…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-91165Low· 2.4
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPost…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-91164Medium· 4.3
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-63330High· 7.7
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session aut…

Twilightwarp-tech · warpgatevia NVD
CVE-2026-63329Medium· 4.9
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends t…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-58491Critical· 9.3
yesterday

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler i…

Midnightwarp-tech · warpgatevia NVD
warp-tech vulnerabilities (CVEs) · VulnSea