Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Globaleaks globaleaks
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:globaleaks:globaleaks:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Globaleaks globaleaks
|
|
| Metrics |
cvssV3_1
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Globaleaks
Globaleaks globaleaks-whistleblowing-software |
|
| Vendors & Products |
Globaleaks
Globaleaks globaleaks-whistleblowing-software |
Fri, 27 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaLeaks performs minimal validation on user-submitted support requests. As a result, arbitrary URLs can be included in support emails sent to administrators. Version 5.0.89 patches the issue. | |
| Title | GlobalLeaks has insufficient URL validation in user support API | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T19:33:52.223Z
Reserved: 2026-03-18T18:55:47.425Z
Link: CVE-2026-33284
No data.
Status : Analyzed
Published: 2026-03-27T15:16:54.643
Modified: 2026-04-10T14:53:45.587
Link: CVE-2026-33284
No data.
OpenCVE Enrichment
Updated: 2026-04-13T14:28:15Z