CVE-2026-100406

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0x2458 🇮🇳@0x2458

    Found a High issue in dbt Core v2 alphas - CVE-2026-100406. :) dbt docs serve had an open query endpoint with no login. If that server was reachable, local files like creds and keys could leak. Fixed in 2.0.0-alpha.5. Upgrade and keep docs serve local. https://github.com/dbt-labs/dbt-core/security/advisories/GHSA-h2j2-2r7g-rff8

    00182738
    1.7K followersView on X

Explore more