PatchSiren

vulnerability-lookup CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM vulnerability-lookup CVE published 2026-09-27

CVE-2026-101041

A vulnerability in the account recovery functionality of the vulnerability-lookup web application allows an attacker to reset a user's password using a valid recovery token due to a time-of-check-to-time-of-use (TOCTOU) race condition. Additionally, a secondary defect permits setting an empty or trivially short password. The affected components include the user account recovery endpoint (/user/confirm_acc [truncated]

MEDIUM vulnerability-lookup CVE published 2026-08-12

CVE-2026-73432

The Vulnerability-Lookup server contains a server-side request forgery (SSRF) vulnerability in its remote-instance synchronization functionality. An authenticated administrator with the admin:access permission could configure a remote instance address that points to internal, loopback, link-local, or cloud metadata HTTP(S) services. When synchronization is performed, the Vulnerability-Lookup server would [truncated]

MEDIUM vulnerability-lookup CVE published 2026-08-12

CVE-2026-73405

An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/<topic> endpoint. The token_required decorator used by the Pub/Sub interface authenticated requests solely by matching the X-API-KEY header against an existing user API key. Unlike the REST API authentication mechanism, it did [truncated]

MEDIUM vulnerability-lookup CVE published 2026-08-12

CVE-2026-73374

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T15:18:33.173Z and has not been modified since then. The vulnerability exists in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from containers.cna.references[].tags[] were directly interpolated into HTML badge elements, bypassing Ji [truncated]

MEDIUM vulnerability-lookup CVE published 2026-08-10

CVE-2026-72761

The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. However, IPv6 transition addresses (NAT64 `64:ff9b::/96`, 6to4 `2002::/16`, Teredo `2001:0000::/32`) are classified as globally routable by IANA, allowing an attacker to register a webhook pointing at a hostname that resolves to a transition address to bypass the SSRF g [truncated]