CVE-2026-75601
- EPSS 0.23%
- Veröffentlicht 26.08.2026 19:53:29
- Zuletzt bearbeitet 09.09.2026 21:09:13
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs,...
CVE-2026-27480
- EPSS 0.35%
- Veröffentlicht 21.02.2026 09:14:30
- Zuletzt bearbeitet 24.02.2026 16:55:37
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify valid users by ...
CVE-2025-67487
- EPSS 0.41%
- Veröffentlicht 09.12.2025 03:35:58
- Zuletzt bearbeitet 11.12.2025 16:06:17
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to access files or directories outside the intended web root folder. SWS g...