CVE-2026-22819 - CERT CVE
ID CVE-2026-22819
Sažetak Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts. This vulnerability is fixed in 0.1.5.
Reference
CVSS
Base: 5.9
Impact: 4.2
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
Zadnje važnije ažuriranje 20-01-2026 - 14:56
Objavljeno 14-01-2026 - 18:16