Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32810

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

Halloy is an IRC application written in Rust. In versions on *nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in 0644 on files and 0755 on directories. This allows any local user on the system to read plaintext credentials stored in config.toml or referenced password_file paths. Commit f180e41061db393acf65bc99f5c5e7397586d9cb patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:halloy:halloy:*:*:*:*:*:*:*:*
Версия до 2026.4 (включая)

EPSS

Процентиль: 7%
0.00175
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 5.5
debian
5 месяцев назад

Halloy is an IRC application written in Rust. In versions on \*nix and ...

EPSS

Процентиль: 7%
0.00175
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-732