High severity7.5OSV Advisory· Published Jan 29, 2026· Updated Jun 17, 2026
CVE-2026-1616
CVE-2026-1616
Description
The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:open_security_issue_management:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:open_security_issue_management:*:*:*:*:*:*:*:*range: <2025.9.0
- (no CPE)range: <2025.9.0
Patches
Vulnerability mechanics
References
1- github.com/RedHatProductSecurity/osim/pull/615nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.