VYPR

search-v2-api

by Red Hat

CVEs (1)

  • CVE-2026-71467HigAug 11, 2026
    risk 0.49cvss 7.5epss

    A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request…