CVE-2026-48050Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `PublicPrefixes` in `cmd/arc/main.go`. The auth middleware short-circuits before the token check on prefix match, so the endpoints are reachable without any authentication. Version 26.06.1 contains a patch. Some workarounds are available. Block `/debug/pprof*` at a reverse proxy / load balancer in front of Arc, restrict Arc's API port to known-trusted networks via firewall rules, and/or patch the running build: comment out `app.Use(pprof.New())` in `internal/api/server.go` and rebuild.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-306CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-22: 2Technical Details · 2026-08-22: 208-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48050 Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(ppro… https://www.cve.org/CVERecord?id=CVE-2026-48050 ----- Traducción: CVE-2026-48050 Arc… http://infoflow.cloud`

    Post summary

    The post announces a new CVE‑2026‑48050 affecting Arc versions before 26.06.1, detailing how the issue involves exposed Go pprof handlers.

    0000022
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48050 Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(ppro… https://www.cve.org/CVERecord?id=CVE-2026-48050

    Post summary

    The passage announces CVE-2026-48050, noting that Arc versions before 26.06.1 expose Go's pprof handlers at `/debug/pprof/*`, thereby revealing a potential vulnerability.

    000001.4K
    58.0K followersView on X

Explore more