Skip to content
Threat Feed

Tag

Credential-Leakage

4 briefs RSS
high advisory

SSRF and Credential Leakage in AWX Notification Backends

CVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.

AWX web-vulnerability ssrf credential-leakage path-traversal arbitrary-file-write remote-code-execution cve-2026-71364
3t 1c
critical advisory

PraisonAI GitHub Actions Credential Leakage Vulnerability (CVE-2026-40313)

PraisonAI versions 4.5.139 and below are vulnerable to credential leakage due to the ArtiPACKED attack, where GitHub Actions workflows using actions/checkout without persist-credentials: false write the GITHUB_TOKEN into the .git/config file, leading to potential exposure in uploaded artifacts and subsequent supply chain compromise.

credential-leakage supply-chain github-actions cve-2026-40313
2r 2t 1c
high advisory

HAPI FHIR Credential Leakage via Improper URL Prefix Matching

HAPI FHIR Core is vulnerable to authentication credential leakage due to improper URL prefix matching on HTTP redirects, allowing attackers to intercept credentials by hosting a domain that is a prefix of a configured FHIR server URL.

HAPI FHIR Core hapi-fhir credential-leakage redirect CVE-2026-34359
2r 1t 2i
high advisory

Glances IP Plugin SSRF Vulnerability Leading to Credential Leakage

A server-side request forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter, allowing attackers to force outbound HTTP requests and potentially leak credentials via the Authorization header.

Glances ssrf credential-leakage python
3r 3t 1i