VYPR

search-v2-api

by Red Hat

CVEs (2)

  • CVE-2026-71469HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory…

  • CVE-2026-71467HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request…