Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55884

Опубликовано: 10 июл. 2026
Источник: nvd
EPSS Низкий

Описание

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.

EPSS

Процентиль: 41%
0.00496
Низкий

Дефекты

CWE-306

Связанные уязвимости

github
3 месяца назад

Tilt: Missing authentication on the network-exposed Tilt HUD server

EPSS

Процентиль: 41%
0.00496
Низкий

Дефекты

CWE-306