Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead passes ssh_options.host an
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58491 | 9.3 CRITICAL | Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter |
| CVE-2026-63330 | 7.7 HIGH | Warpgate: Missing Admin Authorization on Live Recording Stream WebSocket Allows Any Authen |
| CVE-2026-91167 | 6.0 MEDIUM | Warpgate: Missing authorization check on `PUT /users/:id/roles/:role_id` allows any admin |
| CVE-2026-63329 | 4.9 MEDIUM | Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Sp |
| CVE-2026-91164 | 4.3 MEDIUM | Warpgate: API tokens bypass the user's allowed_ip_ranges restriction |
| CVE-2026-91165 | 2.4 LOW | Warpgate: Markup injection in SSO form_post return page via unencoded redirect/error value |
No comments yet