VYPR

Stream

by Cribl

CVEs (3)

  • CVE-2026-45392HigMay 12, 2026
    risk 0.57cvss 8.7epss 0.00

    DOM-based cross-site scripting (XSS) in Cribl Stream before 4.17.1 allows a remote attacker to execute arbitrary JavaScript in the browser of an authenticated user who is tricked into visiting a crafted URL and interacting with the page.

  • CVE-2026-56748HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper validation of symbolic links in the Pack Git import feature in Cribl Stream before 4.18.2 allows a remote authenticated attacker with Pack import and pipeline preview permissions to execute arbitrary code as the Cribl server process via a crafted Git repository…

  • CVE-2026-56747HigJul 27, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper control of generation of code in the JSON Pointer-to-accessor compiler in Cribl Stream before 4.18.2 allows a remote authenticated attacker with edit privileges to execute arbitrary JavaScript on the server via a crafted database connection identifier or pack…