Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91997

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.

EPSS

Процентиль: 27%
0.00337
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697

Связанные уязвимости

CVSS3: 5.3
github
4 дня назад

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name, configured server URL, and WhatsApp instance details.

EPSS

Процентиль: 27%
0.00337
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-697