Логотип exploitDog
bind:CVE-2026-5025
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-5025

Количество 2

Количество 2

nvd логотип

CVE-2026-5025

12 дней назад

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-jpqv-w4r8-mmqw

12 дней назад

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5025

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

CVSS3: 6.5
0%
Низкий
12 дней назад
github логотип
GHSA-jpqv-w4r8-mmqw

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active_user') without any privilege checks (e.g., 'is_superuser').

CVSS3: 6.5
0%
Низкий
12 дней назад

Уязвимостей на страницу