
⚠️⚠️ CVE-2026-2652 (CVSS 8.6): Unauthenticated access to some FastAPI routes when basic-auth is enabled under uvicorn 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJNTGZsb3ci 🎯9.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="MLflow" 🔖Refer: https://huntr.com/bounties/5aeff5f0-49c7-4180-b5cb-c9a046f16756 #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
The post announces CVE‑2026‑2652, describing an unauthenticated access flaw in FastAPI routes under uvicorn, and shares FOFA search results and a bounty link without providing PoC or exploit details.

