Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coralos
Coralos coral Server |
|
| CPEs | cpe:2.3:a:coralos:coral_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Coralos
Coralos coral Server |
|
| Metrics |
cvssV3_1
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Coral-protocol
Coral-protocol coral-server |
|
| Vendors & Products |
Coral-protocol
Coral-protocol coral-server |
Tue, 10 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The Internet of Agents. Prior to 1.1.0, the SSE endpoint (/sse/v1/...) in Coral Server did not strongly validate that a connecting agent was a legitimate participant in the session. This could theoretically allow unauthorized message injection or observation. This vulnerability is fixed in 1.1.0. | |
| Title | Coral Server has insufficient validation of agent identity for SSE connections | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-10T17:40:58.576Z
Reserved: 2026-03-07T17:53:48.815Z
Link: CVE-2026-30968
Updated: 2026-03-10T17:40:53.048Z
Status : Analyzed
Published: 2026-03-10T18:18:55.593
Modified: 2026-03-13T19:49:13.237
Link: CVE-2026-30968
No data.
OpenCVE Enrichment
Updated: 2026-04-16T09:45:31Z