Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | uptrace user_handler.go Login information exposure | |
| First Time appeared |
Uptrace
Uptrace uptrace |
|
| Weaknesses | CWE-200 CWE-209 |
|
| CPEs | cpe:2.3:a:uptrace:uptrace:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uptrace
Uptrace uptrace |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-06T05:00:16.776Z
Reserved: 2026-10-05T18:27:25.680Z
Link: CVE-2026-105707
No data.
Status : Received
Published: 2026-10-06T05:16:38.177
Modified: 2026-10-06T05:16:38.177
Link: CVE-2026-105707
No data.
OpenCVE Enrichment
No data.