Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 11 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Blue-b
Blue-b alienbin |
|
| Vendors & Products |
Blue-b
Blue-b alienbin |
Tue, 10 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops and recreates the MongoDB TTL index on the entire post collection for every new paste submission. When User B submits a paste with a short TTL (e.g., 30 seconds), the TTL index is recreated with expireAfterSeconds: 30 for all documents in the collection. This causes User A's paste (originally set to 7 days) to be deleted after 30 seconds. An attacker can intentionally delete all existing pastes by repeatedly submitting pastes with ttlOption=30s. | |
| Title | Alienbin: TTL Index Race Condition allows unauthorized deletion of other users data | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-11T15:59:20.745Z
Reserved: 2026-03-09T17:41:56.077Z
Link: CVE-2026-31827
Updated: 2026-03-11T15:51:54.061Z
Status : Deferred
Published: 2026-03-10T22:16:20.633
Modified: 2026-04-16T14:47:16.733
Link: CVE-2026-31827
No data.
OpenCVE Enrichment
Updated: 2026-04-16T03:15:22Z