VYPR

flame

by Pawelmalak

CVEs (3)

  • CVE-2026-100501MedSep 25, 2026
    risk 0.42cvss 6.5epss —

    Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate…

  • CVE-2026-100418MedSep 25, 2026
    risk 0.34cvss 5.3epss —

    Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending…

  • CVE-2026-100502MedSep 25, 2026
    risk 0.33cvss 5.0epss —

    Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent…