Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning user's allowed_ip_rang
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58491 | 9.3 CRITICAL | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter |
| CVE-2026-63330 | 7.7 HIGH | Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authen |
| CVE-2026-91167 | 6.0 MEDIUM | Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin |
| CVE-2026-91166 | 5.7 MEDIUM | Warpgate: Web SSH stores a jump host's key against the target's address, so it validates a |
| CVE-2026-63329 | 4.9 MEDIUM | Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Sp |
| CVE-2026-91165 | 2.4 LOW | Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error value |
No comments yet