VYPR
High severity7.5OSV Advisory· Published Jan 29, 2026· Updated Jun 17, 2026

CVE-2026-1616

CVE-2026-1616

Description

The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Red Hat/OsimOSV2 versions
    v2023.11.0, v2023.7.0, v2024.10.0, …+ 1 more
    • (no CPE)range: v2023.11.0, v2023.7.0, v2024.10.0, …
    • (no CPE)range: <2025.9.0
  • cpe:2.3:a:redhat:open_security_issue_management:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:open_security_issue_management:*:*:*:*:*:*:*:*range: <2025.9.0
    • (no CPE)range: <2025.9.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.