CVE-2026-103098

🟡 Monitoruj

Przesyłanie klucza w URL przez niezabezpieczone HTTP umożliwia jego przechwycenie przez atakującego.

CVSS
7.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-10-02 01:16:43 UTC
Ostatnia modyfikacja (NVD)2026-10-02 19:16:39 UTC
Referencje