VYPR

boruta_auth

by Malach It

CVEs (1)

  • CVE-2026-54885Jul 30, 2026
    risk 0.00cvss epss 0.00

    Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints. Three code…