Boruta-Server
Malach-IT · 3 CVEs
CVE-2026-49249
HIGH
Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2
Sep 2, 2026
CVE-2026-55221
MEDIUM
Boruta: OAuth credentials exposed in Boruta business logs
Sep 2, 2026
CVE-2026-53661
HIGH
boruta-server sent sensitive session cookies without the Secure attribute
Jun 11, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-49249 | Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2 | HIGH | 0.40% | Sep 2, 2026 |
| CVE-2026-55221 | Boruta: OAuth credentials exposed in Boruta business logs | MEDIUM | 0.48% | Sep 2, 2026 |
| CVE-2026-53661 | boruta-server sent sensitive session cookies without the Secure attribute | HIGH | 0.32% | Jun 11, 2026 |
Showing 1 to 3 of 3 CVEs