← Back to BugBunny.ai

Hall of Fame

BugBunny.ai CVEs across open source software, developer tooling, infrastructure, and modern AI stacks. Public records show details; reserved entries stay as placeholders.

89

CVEs discovered

69

Public records

9.9

Peak CVSS

20

Reserved placeholders

Severity Timeline

Every BugBunny CVE plotted against time and impact

Hover a point to inspect public advisory metadata or a reserved placeholder. The x-axis tracks disclosure time, while the y-axis uses the numeric CVSS score.

BugBunny mascot firing stylized CVE markers.
Reserved CVEReserved

July 9, 2026

CVE-2026-60076

Reserved disclosure placeholder

Disclosure details are withheld until the CVE or advisory is public.

Reserved

CVSS score

CVSS pending

Details withheldReserved CVE
1086420Mar 21Apr 21May 21Jun 21Jul 21Aug 21Sep 21Oct 21Nov 21Dec 21Jan 22Feb 22Mar 22Apr 22May 22Jun 22Jul 22Aug 22Sep 22Oct 22Nov 22Dec 22Jan 23Feb 23Mar 23Apr 23May 23Jun 23Jul 23Aug 23Sep 23Oct 23Nov 23Dec 23Jan 24Feb 24Mar 24Apr 24May 24Jun 24Jul 24Aug 24Sep 24Oct 24Nov 24Dec 24Jan 25Feb 25Mar 25Apr 25May 25Jun 25Jul 25Aug 25Sep 25Oct 25Nov 25Dec 25Jan 26Feb 26Mar 26Apr 26May 26Jun 26Jul 26
CriticalHighMediumLowDetails withheld

CVE Records (89)

Public CVEs include readable metadata or advisories. Reserved CVEs show only the assigned number and score.

High / critical: 40

NoneReservedCVSS pending

July 9, 2026

CVE-2026-60077

CVE-2026-60077

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
NoneReservedCVSS pending

July 9, 2026

CVE-2026-60076

CVE-2026-60076

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
CriticalPublicCVSS 9.8/10Version 3.1

July 7, 2026

CVE-2026-33264

Apache Airflow DAG Deserialization RCE

Public CVE metadata records unrestricted deserialization class loading in Apache Airflow serialized DAG handling.

Remote Code Execution
Apache AirflowCVE metadata only
HighPublicCVSS 8.7/10Version 3.1

June 30, 2026

CVE-2026-49478

Fulcio OIDC Discovery Redirect SSRF

Public GitHub advisory metadata records OIDC discovery redirect handling issues in Fulcio, including SSRF and JWKS substitution paths.

SSRF
FulcioCVE metadata only
MediumPublicCVSS 6.9/10Version 4.0

June 30, 2026

CVE-2026-44947

Rancher Legacy PRTB Permission Cleanup Issue

Public CVE metadata records missing cleanup in Rancher legacy Project Role Template Binding reconciliation.

Permission Management
RancherCVE metadata only
MediumPublicCVSS 6.8/10Version 3.1

June 24, 2026

CVE-2026-52809

Gogs Password Reset Token Lifetime Issue

Public CVE metadata records password reset tokens remaining valid for the account activation lifetime in Gogs.

Session Management
GogsCVE metadata only
HighPublicCVSS 7.1/10Version 3.1

June 24, 2026

CVE-2026-52808

Gogs Repository Settings Authorization Bypass

Public CVE metadata records write-level collaborators reaching repository administration operations through Gogs API endpoints.

Authorization
GogsCVE metadata only
MediumPublicCVSS 4.4/10Version 3.1

June 24, 2026

CVE-2026-47733

Rocket.Chat Markdown Image URL XSS

Public CVE metadata records missing protocol sanitization for markdown image URLs in Rocket.Chat.

XSS
Rocket.ChatCVE metadata only
NoneReservedCVSS pending

June 12, 2026

CVE-2026-53929

CVE-2026-53929

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
NoneReservedCVSS pending

June 12, 2026

CVE-2026-53928

CVE-2026-53928

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
NoneReservedCVSS pending

June 12, 2026

CVE-2026-53926

CVE-2026-53926

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighPublicCVSS 7.6/10Version 3.1

June 5, 2026

CVE-2026-45726

Omni Imported Cluster CA Key Exposure

Public advisory metadata records reader-level access to imported cluster CA keys through Omni ResourceService.

Information Disclosure
Sidero OmniCVE metadata only
LowPublicCVSS 2.7/10Version 3.1

June 5, 2026

CVE-2026-45723

Omni Image Factory Path Traversal

Public advisory metadata records path traversal in Omni image-factory API handling of talos_version.

Path Traversal
Sidero OmniCVE metadata only
HighPublicCVSS 7.0/10Version 3.1

June 5, 2026

CVE-2026-45720

Omni SAML Session Token Race

Public advisory metadata records a TOCTOU race condition in Omni single-use SAML session token handling.

Race Condition
Sidero OmniCVE metadata only
NoneReservedCVSS pending

June 4, 2026

CVE-2026-50285

CVE-2026-50285

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighPublicCVSS 7.5/10Version 3.1

May 27, 2026

CVE-2026-45090

Dalfox Parameter Analysis Denial of Service

Public CVE metadata records a closed-channel panic in Dalfox parameter analysis that could terminate scans.

Denial of Service
DalfoxCVE metadata only
LowPublicCVSS pending

May 21, 2026

CVE-2026-46554

NocoDB Stale Auth Cache After API Token Deletion

Public advisory metadata records stale authentication cache behavior after API token deletion in NocoDB.

Session Management
NocoDBCVE metadata only
LowPublicCVSS pending

May 21, 2026

CVE-2026-46553

NocoDB Attachment Size Limit Bypass

Public advisory metadata records an attachment size-limit bypass through upload-by-URL in NocoDB.

File Upload
NocoDBCVE metadata only
MediumPublicCVSS 5.4/10Version 3.1

May 15, 2026

CVE-2026-44310

gitsign Empty Certificate Verification Panic

Public CVE metadata records a gitsign verification panic on CMS/PKCS7 signatures with empty certificate sets.

Denial of Service
gitsignCVE metadata only
MediumPublicCVSS 5.3/10Version 3.1

May 15, 2026

CVE-2026-44309

gitsign Git Object Signature Verification Bypass

Public CVE metadata records signature verification differences between raw Git objects and go-git-normalized objects in gitsign.

Signature Verification
gitsignCVE metadata only
HighPublicCVSS 8.2/10Version 4.0

May 14, 2026

CVE-2026-24899

Fleet Windows MDM Azure AD JWT Authentication Bypass

Public CVE metadata records a Windows MDM Azure AD JWT validation issue that allowed tokens from unintended tenants to authenticate.

Authentication Bypass
Fleet Device ManagementCVE metadata only
HighPublicCVSS 8.7/10Version 3.1

May 7, 2026

CVE-2026-43888

Outline Stored XSS

Public advisory metadata records a stored cross-site scripting issue in Outline.

Stored XSS
OutlineCVE metadata only
MediumPublicCVSS 6.5/10Version 3.1

May 7, 2026

CVE-2026-43889

Outline Access Control Issue

Public advisory metadata records an access-control issue in Outline.

Access Control
OutlineCVE metadata only
CriticalPublicCVSS 9.9/10Version 3.1

May 5, 2026

CVE-2026-43999

vm2 Sandbox Escape

Public advisory metadata records a critical vm2 sandbox escape discovered through BugBunny research.

Sandbox Escape
vm2CVE metadata only
HighPublicCVSS 8.5/10Version 3.1

May 5, 2026

CVE-2026-43998

vm2 Sandbox Boundary Bypass

Public advisory metadata records a high-impact vm2 sandbox boundary bypass discovered through BugBunny research.

Sandbox Escape
vm2CVE metadata only
MediumPublicCVSS 6.5/10Version 3.1

May 4, 2026

CVE-2026-42883

Audiobookshelf Access Control Issue

Public advisory metadata records an Audiobookshelf access-control issue discovered through BugBunny research.

Access Control
AudiobookshelfCVE metadata only
MediumPublicCVSS 4.3/10Version 3.1

May 4, 2026

CVE-2026-42884

Audiobookshelf Authorization Issue

Public advisory metadata records an Audiobookshelf authorization issue discovered through BugBunny research.

Authorization
AudiobookshelfCVE metadata only
MediumPublicCVSS 4.3/10Version 3.1

May 4, 2026

CVE-2026-42885

Audiobookshelf Authorization Issue

Public advisory metadata records an Audiobookshelf authorization issue discovered through BugBunny research.

Authorization
AudiobookshelfCVE metadata only
MediumPublicCVSS 4.9/10Version 3.1

May 4, 2026

CVE-2026-42886

Audiobookshelf Authorization Issue

Public advisory metadata records an Audiobookshelf authorization issue discovered through BugBunny research.

Authorization
AudiobookshelfCVE metadata only
HighReservedCVSS 7.8/10Version 3.1

April 22, 2026

CVE-2026-41590

CVE-2026-41590

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
MediumPublicCVSS 5.0/10Version 3.1

April 20, 2026

CVE-2026-41131

OpenFGA Authorization Issue

Public advisory metadata records an OpenFGA authorization issue discovered through BugBunny research.

Authorization
OpenFGACVE metadata only
NoneReservedCVSS pending

April 20, 2026

CVE-2026-40914

CVE-2026-40914

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
NoneReservedCVSS pending

April 18, 2026

CVE-2026-40454

CVE-2026-40454

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
MediumPublicCVSS 5.3/10Version 3.1

April 16, 2026

CVE-2026-40304

zrok Broken Ownership Check

Public advisory metadata records a broken ownership check in zrok that affected frontend record deletion.

Broken Access Control
zrokCVE metadata only
MediumPublicCVSS 6.1/10Version 3.1

April 16, 2026

CVE-2026-40302

zrok OAuth Callback Reflected XSS

Public advisory metadata records a reflected XSS issue in zrok OAuth callback error rendering.

Reflected XSS
zrokCVE metadata only
MediumPublicCVSS 6.5/10Version 3.1

April 10, 2026

CVE-2026-40293

OpenFGA Authorization Issue

Public advisory metadata records an OpenFGA authorization issue discovered through BugBunny research.

Authorization
OpenFGACVE metadata only
HighReservedCVSS 8.7/10Version 3.1

April 10, 2026

CVE-2026-40165

CVE-2026-40165

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighPublicCVSS 7.5/10Version 3.1

April 7, 2026

CVE-2026-35441

Directus Security Boundary Issue

Public advisory metadata records a high-impact Directus security boundary issue discovered through BugBunny research.

Access Control
DirectusCVE metadata only
MediumPublicCVSS 5.0/10Version 3.1

April 6, 2026

CVE-2026-34972

OpenFGA Authorization Model Disclosure

Public advisory metadata records an OpenFGA authorization-model disclosure issue discovered through BugBunny research.

Information Disclosure
OpenFGACVE metadata only
HighPublicCVSS 8.7/10Version 3.1

April 4, 2026

CVE-2026-35214

Budibase Plugin Upload Path Traversal

Public advisory metadata records path traversal in Budibase plugin upload handling, enabling arbitrary directory deletion and file write.

Path Traversal
BudibaseCVE metadata only
MediumPublicCVSS 5.3/10Version 3.1

April 2, 2026

CVE-2026-35413

Directus Security Boundary Issue

Public advisory metadata records a Directus security boundary issue discovered through BugBunny research.

Access Control
DirectusCVE metadata only
HighPublicCVSS 7.1/10Version 3.1

April 2, 2026

CVE-2026-35412

Directus Security Boundary Issue

Public advisory metadata records a high-impact Directus security boundary issue discovered through BugBunny research.

Access Control
DirectusCVE metadata only
HighPublicCVSS 8.1/10Version 3.1

April 1, 2026

CVE-2026-4800

lodash Template Code Injection

Public advisory metadata records code injection through lodash template imports key handling.

Code Injection
lodashCVE metadata only
MediumPublicCVSS 6.5/10Version 3.1

April 1, 2026

CVE-2026-34750

Payload Client Upload Filename Validation

Public advisory metadata records insufficient filename validation in Payload client-upload signed URL endpoints.

File Upload
PayloadCVE metadata only
MediumPublicCVSS 5.4/10Version 3.1

April 1, 2026

CVE-2026-34749

Payload Authentication CSRF Bypass

Public advisory metadata records a CSRF protection bypass in Payload authentication flow.

CSRF
PayloadCVE metadata only
HighPublicCVSS 8.7/10Version 3.1

April 1, 2026

CVE-2026-34748

Payload Admin Stored XSS

Public advisory metadata records stored cross-site scripting in Payload admin panel handling.

Stored XSS
PayloadCVE metadata only
HighPublicCVSS 7.7/10Version 3.1

April 1, 2026

CVE-2026-34746

Payload Upload SSRF

Public advisory metadata records authenticated server-side request forgery in Payload upload functionality.

SSRF
PayloadCVE metadata only
MediumPublicCVSS 4.3/10Version 3.1

March 28, 2026

CVE-2026-34595

Parse Server Authorization Issue

Public CVE metadata records a Parse Server authorization issue discovered through BugBunny research.

Authorization
Parse ServerCVE metadata only
MediumPublicCVSS 5.4/10Version 3.1

March 28, 2026

CVE-2026-34574

Parse Server Authorization Issue

Public CVE metadata records a Parse Server authorization issue discovered through BugBunny research.

Authorization
Parse ServerCVE metadata only
HighPublicCVSS 7.5/10Version 3.1

March 28, 2026

CVE-2026-34573

Parse Server Security Boundary Issue

Public CVE metadata records a high-impact Parse Server security boundary issue discovered through BugBunny research.

Access Control
Parse ServerCVE metadata only
CriticalPublicCVSS 9.1/10Version 3.1

March 28, 2026

CVE-2026-34532

Parse Server Critical Authorization Issue

Public CVE metadata records a critical Parse Server authorization issue discovered through BugBunny research.

Authorization
Parse ServerCVE metadata only
MediumReservedCVSS 5.3/10Version 3.1

March 26, 2026

CVE-2026-34198

CVE-2026-34198

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighReservedCVSS 8.0/10Version 3.1

March 26, 2026

CVE-2026-34171

CVE-2026-34171

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
MediumReservedCVSS 4.3/10Version 3.1

March 26, 2026

CVE-2026-34170

CVE-2026-34170

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
MediumReservedCVSS 5.0/10Version 3.1

March 26, 2026

CVE-2026-34167

CVE-2026-34167

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighReservedCVSS 8.8/10Version 3.1

March 26, 2026

CVE-2026-34158

CVE-2026-34158

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
NoneReservedCVSS pending

March 24, 2026

CVE-2026-34037

CVE-2026-34037

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighReservedCVSS 8.8/10Version 3.1

March 2026

CVE-2026-33016

CVE-2026-33016

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighPublicCVSS 8.1/10Version 3.1

March 2026

CVE-2026-33037

AVideo Default Admin Credential

Official AVideo Docker deployment defaults seeded the admin account with the predictable password `password` when operators left environment defaults unchanged.

Insecure Default Credentials
AVideoRead advisory ->
HighPublicCVSS 8.1/10Version 3.1

March 2026

CVE-2026-33038

AVideo Installer Takeover

AVideo exposed an unauthenticated web installer that let remote attackers initialize fresh deployments with attacker-controlled admin credentials and database settings.

Missing Authentication
AVideoRead advisory ->
HighPublicCVSS 8.6/10Version 3.1

March 2026

CVE-2026-33039

AVideo LiveLinks Redirect SSRF

AVideo validated the initial LiveLinks URL but trusted redirect targets, enabling unauthenticated SSRF into internal services and cloud metadata endpoints.

SSRF
AVideoRead advisory ->
MediumPublicCVSS 5.3/10Version 3.1

March 11, 2026

CVE-2026-31888

Shopware Store API User Enumeration

Shopware exposed whether an email address belonged to a valid customer by returning distinct error codes on Store API login requests.

User Enumeration
ShopwareRead advisory ->
MediumPublicCVSS 6.5/10Version 3.1

March 9, 2026

CVE-2026-30973

Appium Zip Slip Arbitrary File Write

A missing throw in Appium’s ZIP extraction path traversal check made Zip Slip protection non-functional and allowed arbitrary file write.

Arbitrary File Write
@appium/supportRead advisory ->
HighPublicCVSS 8.1/10Version 3.1

March 2026

CVE-2026-29093

AVideo Exposed Memcached Session Store

AVideo’s default docker-compose stack published an unauthenticated memcached instance holding all PHP session data directly to the host network.

Session Exposure
AVideoRead advisory ->
MediumPublicCVSS 5.3/10Version 4.0

March 2026

CVE-2026-28398

NocoDB Stored XSS via Comments and Rich Text

NocoDB rendered attacker-controlled comments and rich text with v-html and no sanitization, enabling stored XSS for viewers of affected records.

Stored XSS
NocoDBRead advisory ->
MediumPublicCVSS 4.9/10Version 4.0

March 2026

CVE-2026-28396

NocoDB Refresh Tokens Survive Password Reset

NocoDB invalidated JWT versions on password reset but failed to delete existing refresh tokens, allowing stolen refresh tokens to survive the reset.

Session Management
NocoDBRead advisory ->
MediumPublicCVSS 4.9/10Version 4.0

March 2026

CVE-2026-28361

NocoDB MCP Token Ownership Bypass

NocoDB’s MCP token service skipped ownership validation, allowing users with sufficient base permissions to manipulate another user’s token if they knew its ID.

Broken Access Control
NocoDBRead advisory ->
MediumPublicCVSS 4.3/10Version 3.1

March 2026

CVE-2026-3351

LXD Certificate Fingerprint Enumeration

LXD’s non-recursive certificate listing bypassed per-object authorization and leaked certificate fingerprints to restricted authenticated users.

Information Disclosure
LXDRead advisory ->
HighReservedCVSS 8.7/10Version 3.1

February 2026

CVE-2026-28445

CVE-2026-28445

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
MediumPublicCVSS 6.9/10Version 4.0

February 2026

CVE-2026-28351

pypdf RunLengthDecode Memory Exhaustion

Crafted RunLengthDecode streams in PDFs could trigger large memory consumption inside pypdf and exhaust process RAM.

Denial of Service
pypdfRead advisory ->
MediumPublicCVSS 6.5/10Version 3.1

February 2026

CVE-2026-28217

Hoppscotch userCollection IDOR

Hoppscotch’s userCollection GraphQL query returned other users’ private collection data without verifying ownership, exposing secrets and request definitions.

IDOR
HoppscotchRead advisory ->
CriticalPublicCVSS 9.1/10Version 3.1

February 24, 2026

CVE-2026-28215

Hoppscotch Infrastructure Configuration Overwrite

Public CVE metadata records unauthenticated infrastructure configuration overwrite in Hoppscotch onboarding configuration handling.

Missing Authentication
HoppscotchCVE metadata only
MediumReservedCVSS 6.5/10Version 3.1

February 2026

CVE-2026-28444

CVE-2026-28444

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
CriticalPublicCVSS 9.9/10Version 3.1

February 2026

CVE-2026-28384

LXD compression_algorithm Host RCE

Multiple LXD API endpoints passed user-controlled compression_algorithm strings into shell-parsed host commands, enabling authenticated host RCE.

Remote Code Execution
LXDRead advisory ->
MediumReservedCVSS 6.6/10Version 3.1

February 2026

CVE-2026-27955

CVE-2026-27955

Disclosure details are withheld until the CVE or advisory is public.

Reserved
Reserved CVEDetails withheld
HighPublicCVSS 7.8/10Version 3.1

February 2026

CVE-2026-27806

Fleet Orbit Tcl Injection Privilege Escalation

Fleet Orbit interpolated a local password into a Tcl/expect script without safe escaping, allowing local users to inject commands and escalate to root.

Local Privilege Escalation
Fleet OrbitRead advisory ->
CriticalPublicCVSS 9.1/10Version 3.1

February 2026

CVE-2026-27471

ERPNext Missing Access Validation

Missing validation on sensitive ERPNext endpoints allowed unauthorized access to employee, invoice, and financial documents.

Improper Access Control
ERPNextRead advisory ->
MediumPublicCVSS 5.4/10Version 3.1

January 2026

CVE-2026-23630

Docmost Mermaid XSS

Unsanitized Mermaid SVG rendering enabled stored XSS against any user viewing a poisoned Docmost page.

XSS
DocmostRead advisory ->
HighPublicCVSS 8.8/10Version 3.1

January 12, 2026

CVE-2026-22807

vLLM auto_map RCE

vLLM loaded Hugging Face auto_map dynamic modules without honoring trust_remote_code, enabling arbitrary Python execution from untrusted models.

Remote Code Execution
vLLMRead advisory ->
HighPublicCVSS 8.2/10Version 3.1

January 12, 2026

CVE-2026-21884

React Router ScrollRestoration XSS

Inline ScrollRestoration scripts failed to escape </script> sequences during SSR, allowing attacker-controlled XSS.

XSS
React RouterRead advisory ->
HighPublicCVSS 7.5/10Version 3.1

November 2025

CVE-2025-64756

glob CLI Command Injection

The glob CLI passed attacker-controlled filenames into shell execution paths, making malicious repositories executable.

Command Injection
glob CLIRead advisory ->
CriticalPublicCVSS 9.1/10Version 3.1

October 2025

CVE-2025-61686

React Router Path Traversal

Crafted session identifiers escaped React Router file session storage directories and enabled arbitrary file overwrite.

Path Traversal
React RouterRead advisory ->
CriticalPublicCVSS 9.8/10Version 3.1

September 2025

CVE-2025-61622

Apache Fory Pickle RCE

Unsupported objects in pyfory/pyfury fell back to pickle.loads, enabling arbitrary code execution from crafted serialized data.

Remote Code Execution
Apache ForyRead advisory ->
MediumPublicCVSS 5.3/10Version 3.1

August 2025

CVE-2025-59792

Apache Kvrocks Credential Exposure

Kvrocks MONITOR output leaked plaintext AUTH credentials, exposing passwords to low-privilege observers.

Information Disclosure
Apache KvrocksRead advisory ->
MediumPublicCVSS 5.4/10Version 3.1

August 2025

CVE-2025-59790

Apache Kvrocks Privilege Escalation

Namespace token validation flaws in Kvrocks allowed lower-privilege users to cross privilege boundaries.

Privilege Escalation
Apache KvrocksRead advisory ->
HighPublicCVSS 7.6/10Version 3.1

July 2025

CVE-2025-59057

React Router Stored XSS

A stored XSS condition in React Router allowed attacker-supplied markup to persist and execute in downstream applications.

XSS
React RouterRead advisory ->
CriticalPublicCVSS 9.8/10Version 3.1

June 2025

CVE-2025-58434

Flowise Account Takeover

Flowise leaked password reset material in a way that enabled full account takeover across local and cloud deployments.

Account Takeover
FlowiseRead advisory ->
HighPublicCVSS 7.2/10Version 3.1

May 6, 2021

CVE-2021-23337

lodash Command Injection

Public advisory metadata records command injection in lodash template handling.

Command Injection
lodashCVE metadata only
MediumPublicCVSS 5.9/10Version 3.1

March 29, 2021

CVE-2020-24392

twitter-stream Improper Certificate Validation

Public advisory metadata records improper certificate validation in twitter-stream; the local historical tracker links this CVE to the Huginn advisory context.

Certificate Validation
twitter-stream / HuginnCVE metadata only

Want coverage like this?

BugBunny runs coordinated AI agents to surface exploitable issues before attackers do, then packages the results into audit-ready findings and CVE-quality disclosures.

Hall of Fame | BugBunny.ai | BugBunny.ai