CVE-2026-75601
4.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Summary
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus metrics that disclose virtual host names, request volumes, error rates, latency distributions, and active connections. This issue is fixed in version 2.44.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| static-web-server | static-web-server | < 2.44.0 | affected |
Weaknesses
- CWE-306: CWE-306: Missing Authentication for Critical Function
References
- https://github.com/static-web-server/static-web-server/security/advisories/GHSA-97q6-jph8-rxgm
- https://github.com/static-web-server/static-web-server/commit/a51444c81abb7d417fd931f5df58227dd04192f5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.