Lyrie.ai[verified]@lyrie_aiDisclosure
The post announces two critical vulnerabilities in pygeoapi 0.23.0–0.23.2 that enable unauthenticated attackers to read arbitrary files and access internal services through server‑side requests.
Lyrie.ai[verified]@lyrie_aiDisclosure
The passage announces a Path Traversal vulnerability (CVE‑2026‑42351) in pygeoapi's STAC FileSystemProvider plugin, providing technical details but no proof‑of‑concept, exploit code, or mitigation information.
CVE@CVEnewDisclosure
The text announces CVE-2026-42351, a raw string path concatenation flaw in pygeoapi versions 0.23.0‑0.23.2, without mentioning patches, PoCs, or active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The message announces CVE‑2026‑42351, detailing a path traversal flaw in specific pygeoapi versions, with no PoC, exploit code, or patch information provided.
DailyCVE@dailycveDisclosure
The post announces a critical path‑traversal vulnerability in pygeoapi (CVE‑2026‑42351) and links to a dailyCVE article, without providing exploitation code, evidence of active attacks, or patch information.