HIGH
nessshon
CVE published 2026-07-28
CVE-2026-54635
The pytonapi SDK for TONAPI has a vulnerability in TonapiWebhookDispatcher from version 2.0.0 to 2.2.0 due to improper validation of the Authorization header when registering webhook handlers with custom paths. This allows unauthenticated remote attackers to POST forged payloads to custom webhook endpoints and trigger victim-defined handlers. The vulnerability has a HIGH severity score of 7.5 and affects [truncated]