CVE-2026-59720
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist t
CVSS
7.5
Alto
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Publicado: 9 jul 2026 · Última mod.: 10 jul 2026 · CWE-200 · CWE-284
0.3%EPSS · 30 días0.3%
2026-07-102026-07-21
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and potentially expose sensitive API data. This issue is fixed in version 2026.6.0.
- github.comhttps://github.com/hoppscotch/hoppscotch/commit/e4332110d455a3012d5c77a9186bc4aa096e34f2
- github.comhttps://github.com/hoppscotch/hoppscotch/pull/6410
- github.comhttps://github.com/hoppscotch/hoppscotch/releases/tag/2026.6.0
- github.comhttps://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-c68f-wr5p-j6jf
- github.comhttps://github.com/hoppscotch/hoppscotch/security/advisories/GHSA-c68f-wr5p-j6jf
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-63047——
———The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.5hCVE-2026-567466.5 MED—
——0Netty is a network application framework for development of protocol servers and clients. Versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, are vulnerable to security control bypass during the origin evaluation process. CorsHandler provides a shortCircuit() configuration designed to reject unauthorized cross-origin requests immediately, acting as a security control before requests reach the application. However, due to a logical operator error in the origin evaluation process, this protection can be entirely bypassed. An attacker can bypass the short-circuit mechanism by sending a request with an Origin: null header. This failure forwards unauthorized requests to the backend application, bypassing intended access controls. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.15hCVE-2026-472477.5 ALT—
——0libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.15hCVE-2026-43945——
——0FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled). Version 1.3.1 fixes the issue.15hCVE-2026-565793.1 BAJ—
——0HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.18hCVE-2026-565782.2 BAJ—
——0HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.18h