Sub2api
Wei-Shaw · 2 CVEs
CVE-2026-73079
HIGH
Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstre…
Aug 11, 2026
CVE-2026-27812
HIGH
Sub2API Vulnerable to Password Reset Poisoning via Host Header Trust Issue, Leading to Account Takeover
Feb 26, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-73079 | Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account creden… | HIGH | 0.39% | Aug 11, 2026 |
| CVE-2026-27812 | Sub2API Vulnerable to Password Reset Poisoning via Host Header Trust Issue, Leading to Account Takeover | HIGH | 0.44% | Feb 26, 2026 |
Showing 1 to 2 of 2 CVEs