VYPR
Moderate severityOSV Advisory· Published Jan 14, 2026· Updated Jan 14, 2026

Outray has a Race Condition in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts

CVE-2026-22819

Description

Outray openSource ngrok alternative. Prior to 0.1.5, this vulnerability allows a user i.e a free plan user to get more than the desired subdomains due to lack of db transaction lock mechanisms in main/apps/web/src/routes/api/$orgSlug/subdomains/index.ts. This vulnerability is fixed in 0.1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
outraynpm
< 0.1.50.1.5

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.