CVE-2026-45728
📛 CVE Title
(no title)
Description
Algernon: Single-file mode unconditionally enables debug mode
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-45728 on 2026-07-09. Shown when MITRE's text differs from the cvelistV5 mirror.
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path instead of a directory, singleFileMode is set to true and debugMode is forcibly enabled. debugMode activates the PrettyError renderer, which on any Lua or template error response dumps the absolute path of the file that errored, complete byte contents of that file, and exception or parser error text. This response is served with HTTP 200 OK to whoever sent the request that triggered the error. Any client able to reach the server and able to provoke a runtime error in the served script obtains the full server-side source of that script and of any sibling Lua data file consulted during the request. This vulnerability is fixed in 1.17.7.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.5 / 10
- CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Effective score
- 7.5 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-45728
- Linked Threat
- CVE-2026-45728 — CVE-2026-45728
NVD / KEV / EPSS data refreshed 2026-05-25 00:12 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-31868
EUVD enrichment is queued; refresh the page in a few seconds.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (4)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://github.com/xyproto/algernon/security/advisories/GHSA-fwqx-8365-9983 tenable:github.com
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45728 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45728 tenable:www.cve.org
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-05-26 02:58 UTC -
web:forums.ea.com
Broken and Updated Sims 4 Mods and CC: patch 1.124, May 12 and 21, 2026 About This Thread This thread tracks Sims 4 mods and CC that have been "broken" or made obsolete by game update 1.124, May 12, 2026 , and the May 21 hotfix, or declared unsupported by their creators.
2026-05-26 02:58 UTC -
web:robertsspaceindustries.com
Hi Everyone! Time again for another Hotfix Central thread to keep you all up to date on things going on outside of the normal patch cycle in SC Alpha 4.8 LIVE! This will be a living document of...
2026-05-26 02:58 UTC -
web:support.microsoft.com
The April 14, 2026 update for Windows Server 2022 includes security and cumulative reliability improvements in .NET Framework 3.5 and 4.8. We recommend that you apply this update as part of your regular maintenance routines. Before you install this update, see the Prerequisites and Restart requirement sections. Summary Security Improvements CVE - 2026 -32178 - .NET Framework Remote Code Execution ...
2026-05-26 02:58 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-26 02:58 UTC -
web:www.fda.gov
XD Investments LLC of Houston, TX, is voluntarily recalling approximately 448 Boxes of Better Weather Fix Elixir products, including all flavors and variations, because FDA analysis found the ...
2026-05-26 02:58 UTC -
web:www.leagueoflegends.com
League of Legends Patch 26.5 Notes Welcome to the official patch of First Stand, the first major international tournament of the year!
2026-05-26 02:58 UTC -
web:www.lotro.com
Here are the Release Notes for Update 48.3: A Glorious Hunt, Patch 3 released on Wednesday, May 20, 2026 .
2026-05-26 02:58 UTC -
web:www.nexusmods.com
This is a UTOC Signature Bypass patch for Marvel Rivals that allows you to modify the game to load new pak/utoc/ucas files without needing a .sig file. WARNING!!!
2026-05-26 02:58 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-26 02:58 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.