MEDIUMVulnerability

CVE-2026-75601

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus metrics that disclose virtual host names, request volumes, error rates, latency distributions, and active connections. This issue is fixed in version 2.44.0.

Properties

severity
MEDIUM
score
4.3
epss_score
0.0023
cve_id
CVE-2026-75601
signal_observed_at
2026-09-15T21:12:47+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
published_at
2026-08-26T20:18:00.160
last_modified
2026-09-09T21:09:13.080
epss_percentile
0.13957

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Missing Authentication for Critical Function

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75601 — Ninja Signal Threat Intelligence | Ninja Signal