Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-39364

Опубликовано: 07 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, .crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

A flaw was found in Vite, a frontend tooling framework for JavaScript. On the Vite development server, a remote attacker could exploit this vulnerability by appending specific query parameters, such as ?raw, to requests. This allows the attacker to bypass security restrictions and retrieve sensitive files, including environment variables (.env) and certificate files (
.crt), which should otherwise be blocked. This information disclosure could lead to further compromise of the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4rhacs-eng/release-mainNot affected
Red Hat Ansible Automation Platform 2automation-controllerWill not fix
Red Hat Ansible Automation Platform 2automation-eda-controllerNot affected
Red Hat Ansible Automation Platform 2automation-gatewayNot affected
Red Hat Ansible Automation Platform 2automation-platform-uiNot affected
Red Hat Ansible Automation Platform 2redhat-user-workloads/gateway-rhel9Not affected
Red Hat Build of KeycloakviteWill not fix
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Affected
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Affected
Red Hat Build of Podman Desktop - Tech Previewredhat-user-workloads/bootc-extAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-472
https://bugzilla.redhat.com/show_bug.cgi?id=2456181vite: Vite: Information disclosure via query parameter manipulation on the development server

EPSS

Процентиль: 80%
0.02095
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This vulnerability is fixed in 7.3.2 and 8.0.5.

CVSS3: 7.5
debian
4 месяца назад

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to bef ...

github
4 месяца назад

Vite: `server.fs.deny` bypassed with queries

EPSS

Процентиль: 80%
0.02095
Низкий

7.5 High

CVSS3