Threats Tagged 'cwe-598'
View all threats tagged with 'cwe-598'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-598'
Click on any threat for detailed analysis and mitigation recommendations
0 Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in, AshAuthentication.Phoenix.Components.Password.SignInForm builds the sign_in_with_token path with the freshly issued user.__metadata__.token as a query parameter and redirects the browser to it with a GET. The token therefore travels in the request line, where web servers, reverse proxies, request telemetry and the browser's own history record it, all of which outlive the request and are ordinarily less protected than session storage. The redirect destination is restricted to a local path, so this is not an open redirect; the exposure is the retention of a live credential. This issue affects ash_authentication_phoenix: from 1.7.0 before 2.17.4 and from 3.0.0-rc.0 before 3.0.0-rc.11; ash_authentication: from 3.10.5 before 4.15.0 and from 5.0.0-rc.0 before 5.0.0-rc.14. Join the discussion | CVE Database V5 | 09/17/2026, 13:09:31 UTC Added: 09/17/2026, 13:17:28 UTC |
0 canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing access logs, proxy logs, and APM traces to persist the credentials in plaintext. When a token request fails, OAuth2::obtainAccessToken() also passes the credential-bearing Guzzle request URI into AuthorizationFailedException, so application logs and error trackers can record the same secrets. An attacker with access to affected telemetry can obtain Canto credentials and use them to request access tokens for the tenant. This issue is fixed in version 3.0.0. Join the discussion | CVE Database V5 | 09/15/2026, 17:30:29 UTC Added: 09/15/2026, 17:48:29 UTC |
0 Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0. Join the discussion | CVE Database V5 | 09/14/2026, 17:06:23 UTC Added: 09/14/2026, 17:33:54 UTC |
0 CVE-2026-82181 is a medium severity vulnerability in Le-yan Medical Practice Management System version 2.4.2.8. It involves the use of the GET request method with sensitive query strings, which can expose sensitive information in browser history or log files accessible to unauthenticated remote attackers. Join the discussion | CVE Database V5 | 08/28/2026, 11:52:48 UTC Added: 08/28/2026, 15:38:07 UTC |
0 CVE-2026-76179 is a critical vulnerability in the Ebyte NA111-M Firmware that involves improper protection of authentication tokens in the web management interface. The tokens are insufficiently protected during client-side session handling, allowing attackers with access to session information to obtain and reuse valid tokens. This can enable attackers to impersonate authenticated users and gain unauthorized access to device management functions. Join the discussion | CVE Database V5 | 08/27/2026, 21:22:53 UTC Added: 08/28/2026, 11:04:29 UTC |
0 Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API plugin JwtAuthenticator::extractBearerToken() accepts a JWT from the token URL query parameter on every /api/v1 route, including state-changing endpoints. Request URLs consequently expose valid access tokens through Apache, proxy, and CDN logs, browser history, and Referer headers, allowing a party with access to those records to reuse the token with the owner's API privileges. This issue is fixed in version 1.0.0-rc.16. Join the discussion | CVE Database V5 | 08/19/2026, 15:53:08 UTC Added: 08/19/2026, 16:08:13 UTC |
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context. Join the discussion | CVE Database V5 | 08/11/2026, 20:49:56 UTC Added: 08/11/2026, 21:11:57 UTC |
CVE-2026-14838 is a vulnerability in Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources product, versions 26.0 before 26.1. It involves the use of the GET request method with sensitive query strings, which can lead to session hijacking. The vulnerability has a high severity score of 7.4 (CVSS 3.1). No official patch or remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 08/04/2026, 08:42:27 UTC Added: 08/04/2026, 09:18:34 UTC |
0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs). This issue has been patched in version 0.3.2. Join the discussion | CVE Database V5 | 07/28/2026, 18:19:39 UTC Added: 07/28/2026, 18:22:44 UTC |
0 IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs. Join the discussion | CVE Database V5 | 07/17/2026, 19:35:19 UTC Added: 07/18/2026, 11:08:28 UTC |
Showing 1 to 10 of 35 results