VYPR

EPDS

by GAO

CVEs (2)

  • CVE-2026-54106Jun 18, 2026
    risk 0.00cvss epss

    The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator…

  • CVE-2026-54103Jun 18, 2026
    risk 0.00cvss epss

    The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote,…