CVE-2026-40035Disclosure(ryandfir / unfurl)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch ryandfir unfurl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a string and passed directly to app.run(), causing any non-empty string to evaluate truthy, allowing attackers to access the Werkzeug debugger and disclose sensitive information or achieve remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-489

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unfurl

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-09)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
unfurl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 1Mentions · 2026-04-09: 2Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 204-0804-09
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-081
Disclosure1
2026-04-092
Disclosure1Patch1
Full discourse3 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-40035 — CVSS 9.1/10 █████████░ Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/BwF1EuA3Uq

    Post summary

    The tweet announces CVE-2026-40035 as a critical flaw involving improper input validation in Flask config parsing and urges deployment of a patch.

    1000043
    16 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-40035: CRITICAL] Beware of Unfurl through 2025.08: improper input validation in config parsing enables Flask debug mode by default, leading to potential cyber attacks on vulnerable systems.#cve,CVE-2026-40035,#cybersecurity https://cvefind.com/CVE-2026-40035

    Post summary

    The statement announces a critical CVE (CVE-2026-40035) involving improper input validation that leaves Flask debug mode enabled by default, potentially allowing remote exploitation.

    0000038
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40035: dfir-unfurl - Werkzeug Debugger ... String-to-boolean coercion strikes again: dfir-unfurl's config parser enables Werkzeug debugger by default, turning DFI... https://zerodaysignal.com/vulnerability/CVE-2026-40035 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-40035, detailing how a default config setting in dfir‑unfurl allows the Werkzeug debugger to be enabled, but it does not provide PoC evidence, exploit code, or evidence of active exploitation.

    0000086
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appryandfirunfurl---

Explore more