All 3 CVE vulnerabilities found in boruta-server, with AI-generated Chinese analysis, references, and POCs.
Vendor: malach-it
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-49249 | Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2 CWE-400 | 7.1 | High | 2026-09-02 |
| CVE-2026-55221 | Boruta: OAuth credentials exposed in Boruta business logs CWE-532 | 6.5 | Medium | 2026-09-02 |
| CVE-2026-53661 | boruta-server sent sensitive session cookies without the Secure attribute CWE-614 | - | - | 2026-06-11 |
All 3 known CVE vulnerabilities affecting boruta-server with full Chinese analysis, references, and POCs where available.