THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75601 (MEDIUM 4.3) — Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated r

[NVD] CVE-2026-75601 (MEDIUM 4.3) — Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated r

mednvdPublished 2026-08-26

CVE-2026-75601 CVSS: 4.3 MEDIUM Published: 2026-08-26T20:18:00.160

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus metrics that d

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75601