VYPR

Evolution API

by Evolution Foundation

CVEs (1)

  • CVE-2026-91997MedSep 15, 2026
    risk 0.34cvss 5.3epss

    evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing…