Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends the authenticated userna
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58491 | 9.3 CRITICAL | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter |
| CVE-2026-63330 | 7.7 HIGH | Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authen |
| CVE-2026-91167 | 6.0 MEDIUM | Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin |
| CVE-2026-91166 | 5.7 MEDIUM | Warpgate: Web SSH stores a jump host's key against the target's address, so it validates a |
| CVE-2026-91164 | 4.3 MEDIUM | Warpgate: API tokens bypass the user's allowed_ip_ranges restriction |
| CVE-2026-91165 | 2.4 LOW | Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error value |
No comments yet