PatchSiren

coderamp-labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH coderamp-labs CVE published 2026-08-28

CVE-2026-82289

Gitingest through 0.3.1 fails to properly validate hostnames, accepting any host with a git., gitlab., or github. prefix. This allows attackers to submit URLs with attacker-controlled hostnames, triggering outbound connections to arbitrary hosts and disclosing GitHub personal access tokens via HTTP basic credentials. The vulnerability enables attackers to bypass hostname validation, potentially leading to [truncated]