PatchSiren

openfaas CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM openfaas CVE published 2026-08-27

CVE-2026-81664

The OpenFaaS gateway vulnerability (CVE-2026-81664) exposes telemetry data due to an authentication bypass in versions 0.27.11 through 0.27.13. This issue allows unauthorized access to resource and invocation metrics. Affected users should review gateway configurations, verify basic_auth settings, and consider upgrading to version 0.27.14 or later. The CVE record was published on 2026-08-27T17:20:55.970Z. [truncated]