CVE-2026-56021
Published Jun 18, 2026Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
- evidence mentions
- 4
- Buzz score
- 32.6
CWE archive
3 CVEs tagged with CWE-777 — 0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.
Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against…
ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.