Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hotcrp:hotcrp:3.1:*:*:*:*:*:*:* |
Tue, 20 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hotcrp
Hotcrp hotcrp |
|
| Vendors & Products |
Hotcrp
Hotcrp hotcrp |
Mon, 19 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HotCRP is conference review software. Starting in commit aa20ef288828b04550950cf67c831af8a525f508 and prior to commit ceacd5f1476458792c44c6a993670f02c984b4a0, authors with at least one submission on a HotCRP site could use the document API to download any documents (PDFs, attachments) associated with any submission. The problem was patched in commit ceacd5f1476458792c44c6a993670f02c984b4a0. | |
| Title | HotCRP vulnerable to exposure of submitted documents | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-20T21:40:57.565Z
Reserved: 2026-01-16T21:02:02.900Z
Link: CVE-2026-23878
Updated: 2026-01-20T21:40:55.263Z
Status : Analyzed
Published: 2026-01-19T19:16:04.963
Modified: 2026-02-05T18:39:14.693
Link: CVE-2026-23878
No data.
OpenCVE Enrichment
Updated: 2026-04-18T05:15:15Z