PatchSiren

ServerCo CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ServerCo CVE published 2026-06-16

CVE-2026-10303

CVE-2026-10303 is a HIGH severity vulnerability in ServerCo getssl version 2.49 and prior. The issue involves improper validation of ACME challenge tokens, which could allow an attacker to achieve unauthorized file write/path traversal effects and potentially lead to remote command injection. This vulnerability is an instance of CWE-73, 'External control of file name or path.'