Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55883— Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream

AI Predicted 5.3 Difficulty: Easy EPSS 0.22% · P13

Affected Version Matrix 1

VendorProductVersion RangeStatus
tilt-devtilt>= 0.24.0, < 0.37.4affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-55883

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
Source: CVE Program / CVE List V5
Vulnerability Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoint and the upgrader accepts clients that omit an Origin header. When the HUD is network-exposed, an attacker who can reach the listener can open the HUD WebSocket and receive the full view stream, including session state, Tiltfile contents, resource statuses, and continued updates. This issue is fixed in version 0.37.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5
Vulnerability Title
Tilt Dev Tilt 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tilt Dev Tilt是Tilt Dev团队的一款持续集成与交付的微服务开发工具。 Tilt Dev Tilt 0.24.0版本至0.37.3版本存在输入验证错误漏洞,该漏洞源于CSRF令牌认证机制缺陷,未经身份验证的端点可分发令牌且WebSocket接受缺少Origin标头的客户端,导致网络暴露环境下攻击者可通过访问监听器打开HUD WebSocket获取完整视图流,包括会话状态、Tiltfile内容、资源状态及持续更新。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
tilt-devtilt >= 0.24.0, < 0.37.4 -

II. Public POCs for CVE-2026-55883

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55883

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55883 (2)

Vendor Advisories for CVE-2026-55883 (1)

Vendor Pages for CVE-2026-55883 (1)

Same Patch Batch · tilt-dev · 2026-07-10 · 3 CVEs total

CVE-2026-558849.2 CRITICALTilt: Missing authentication on the network-exposed Tilt HUD server
CVE-2026-55882Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

IV. Related Vulnerabilities

V. Comments for CVE-2026-55883

No comments yet


Leave a comment