Skip to main content

CVEs

CVE-2026-44585

CVSS 5.4, moderate.

Ticket creation didn't check that you actually owned the service you referenced. By changing the service ID in the request, you could create a ticket tied to someone else's service. No direct access to their data, but support staff reviewing tickets could end up looking at another customer's service instead.

GHSA-x93q-x9pc-w5hw

CVE-2026-44584

CVSS 4.3, moderate.

This one's about email verification not resetting when you change your email. Verify an account with a real address, then swap the email to whatever you want, and it stays marked as verified, no re-confirmation needed. Basically lets you fake ownership of an email address you don't control, on anything gated behind that verified flag.

GHSA-rv89-wch8-c574