All 2 CVE vulnerabilities found in sub2api, with AI-generated Chinese analysis, references, and POCs.
Vendor: Wei-Shaw
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials CWE-22 | 8.5 | High | 2026-08-11 |
| CVE-2026-27812 | Sub2API Vulnerable to Password Reset Poisoning via Host Header Trust Issue, Leading to Account Takeover CWE-116 | 8.8AI | HighAI | 2026-02-26 |
All 2 known CVE vulnerabilities affecting sub2api with full Chinese analysis, references, and POCs where available.