Threats Tagged 'ghsa-8gv5-4q99-4cxm'
View all threats tagged with 'ghsa-8gv5-4q99-4cxm'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-8gv5-4q99-4cxm'
Click on any threat for detailed analysis and mitigation recommendations
An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE)… (CVE-2026-73405)CVE-2026-73405 0 An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed user accounts to subscribe to Server-Sent Events (SSE) streams via the /pubsub/subscribe/<topic> endpoint. This occurred because the SSE interface authenticated requests only by matching the X-API-KEY header without verifying if the account was active and confirmed. As a result, newly created accounts could access SSE streams that should be restricted to active, confirmed users, potentially exposing sensitive streaming data such as unmoderated comments. The issue stems from inconsistent authorization enforcement between the REST API and the SSE streaming interface. A patch has been developed to require accounts to be both active and confirmed before accessing Pub/Sub streams, aligning SSE authorization with the REST API. Join the discussion | GCVE Database | 08/12/2026, 15:30:50 UTC Added: 08/12/2026, 16:11:06 UTC |
Showing 1 to 1 of 1 result