Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26374 | "Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communication. If a user accesses a crafted URL, an attacker may obtain the JWT (JSON Web Token). |
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN47404248/ |
|
Tue, 02 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ios Google android Gunosy Gunosy gunosy |
|
| Vendors & Products |
Apple
Apple ios Google android Gunosy Gunosy gunosy |
Tue, 02 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | "Gunosy" App contains a vulnerability where sensitive information may be included in the application's outbound communication. If a user accesses a crafted URL, an attacker may obtain the JWT (JSON Web Token). | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-09-02T13:49:26.120Z
Reserved: 2025-08-27T02:46:14.686Z
Link: CVE-2025-44017
Updated: 2025-09-02T13:49:23.025Z
Status : Deferred
Published: 2025-09-02T08:15:30.977
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-44017
No data.
OpenCVE Enrichment
Updated: 2025-09-02T15:23:02Z
EUVD