VYPR

boruta_auth

by Malach It

Source repositories

CVEs (1)

  • CVE-2026-54885MedJul 30, 2026
    risk 0.38cvss epss 0.00

    Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints. Three code…